Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
LMSetup.exe

Overview

General Information

Sample Name:LMSetup.exe
Analysis ID:562516
MD5:c915a8370a016f079adfea57cc00b46f
SHA1:07b31c5bcad7bc0e9da24a46f180001709e1dbe5
SHA256:315d36c57e181df7ee2730361847fb4311eef889df19c2ba8bd00759c46465e5
Infos:

Detection

Score:10
Range:0 - 100
Whitelisted:false
Confidence:40%

Signatures

Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Uses code obfuscation techniques (call, push, ret)
Creates files inside the system directory
PE file contains sections with non-standard names
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
Found dropped PE file which has not been started or loaded
Uses the system / local time for branch decision (may execute only at specific dates)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Abnormal high CPU Usage
Creates a DirectInput object (often for capturing keystrokes)
Is looking for software installed on the system
Drops files with a non-matching file extension (content does not match file extension)
Searches for the Microsoft Outlook file path
PE file contains strange resources
Allocates memory with a write watch (potentially for evading sandboxes)
Drops PE files
Contains functionality to read the PEB
Drops PE files to the windows directory (C:\Windows)
Found evasive API chain checking for process token information
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Found large amount of non-executed APIs
Uses Microsoft's Enhanced Cryptographic Provider
Creates a process in suspended mode (likely to inject code)
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)

Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample may be VM or Sandbox-aware, try analysis on a native machine
Sample may offer command line options, please run it with the 'Execute binary with arguments' cookbook (it's possible that the command line switches require additional characters like: "-", "/", "--")
  • System is w10x64
  • LMSetup.exe (PID: 6100 cmdline: "C:\Users\user\Desktop\LMSetup.exe" MD5: C915A8370A016F079ADFEA57CC00B46F)
    • LMSetup.exe (PID: 5264 cmdline: "C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe" -burn.clean.room="C:\Users\user\Desktop\LMSetup.exe" -burn.filehandle.attached=556 -burn.filehandle.self=576 MD5: ED2B2F8988D6123D440982052A65D364)
      • cmd.exe (PID: 5300 cmdline: cmd" /c C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe "C:\Users\user\Desktop\LMSetup.exe" -nologo -x "C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba MD5: F3BDBE3BB6F734E357235F4D5898582D)
        • conhost.exe (PID: 2944 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
        • dark.exe (PID: 6416 cmdline: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe "C:\Users\user\Desktop\LMSetup.exe" -nologo -x "C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba" MD5: 6F5BF63BB69D04CFBF2BDB336BF3A767)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008DA0BB DecryptFileW,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008FFA62 CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008D9E9E DecryptFileW,DecryptFileW,
Source: LMSetup.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\cs\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\da\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\de-de\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\el\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\en-gb\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\en-us\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\es-es\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\fi\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\fr-fr\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\hu\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\it-it\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\ja\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\nl-nl\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\no-no\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\pl\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\pt-br\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\pt-pt\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\ru\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\sv-se\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\tr-tr\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\zh-cn\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\zh-tw\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\cs\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\da\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\de-de\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\en-gb\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\en-us\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\es-es\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\fi\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\fr-fr\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\hu\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\it-it\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\ja\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\nl-nl\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\no-no\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\pl\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\pt-br\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\pt-pt\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\ru\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\sv-se\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\tr-tr\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\zh-cn\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\zh-tw\readme.txtJump to behavior
Source: LMSetup.exeStatic PE information: certificate valid
Source: LMSetup.exeStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\DependencyExtension\WixDependencyExtension.pdb source: dark.exe, dark.exe, 00000018.00000002.556392871.0000000002EF2000.00000002.00000001.01000000.00000020.sdmp
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\burn.pdb source: LMSetup.exe
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixUtilExtension\WixUtilExtension.pdb| source: dark.exe, 00000018.00000002.557734588.0000000005862000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixIIsExtension\WixIIsExtension.pdb source: dark.exe, 00000018.00000002.556830066.0000000005472000.00000002.00000001.01000000.00000025.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixVSExtension\WixVSExtension.pdb source: dark.exe, 00000018.00000002.559434031.0000000005ED2000.00000002.00000001.01000000.0000002A.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixGamingExtension\WixGamingExtension.pdb source: dark.exe, 00000018.00000002.556500646.0000000002F62000.00000002.00000001.01000000.00000023.sdmp
Source: Binary string: pdbaMicrosoft.Tools.WindowsInstallerXml.Xsd.pdbs.xsdUhttp://schemas.microsoft.com/wix/2006/pdbs source: dark.exe, 00000018.00000002.556968676.0000000005592000.00000002.00000001.01000000.0000001D.sdmp, u32.24.dr
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\FW5DeviceApp\JBusCore.Native\JBusModules\JBM_Resolver\vs12\bin\Release\Win32\JBM_Resolver_vs12.pdb,, source: JBM_Resolver_vs12.dll.5.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixUIExtension\WixUIExtension.pdbL source: dark.exe, 00000018.00000002.558081633.0000000005B32000.00000002.00000001.01000000.00000029.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixGamingExtension\WixGamingExtension.pdb( source: dark.exe, 00000018.00000002.556500646.0000000002F62000.00000002.00000001.01000000.00000023.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\dark\dark.pdb source: dark.exe, dark.exe, 00000018.00000000.486739438.0000000000B02000.00000002.00000001.01000000.0000001C.sdmp
Source: Binary string: Microsoft.Tools.WindowsInstallerXml.Xsd.pdbs.xsd source: dark.exe, 00000018.00000002.556968676.0000000005592000.00000002.00000001.01000000.0000001D.sdmp, u32.24.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixNetfxExtension\WixNetFxExtension.pdb source: dark.exe, 00000018.00000002.556908564.0000000005532000.00000002.00000001.01000000.00000026.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixHttpExtension\WixHttpExtension.pdb source: dark.exe, 00000018.00000002.556791687.00000000053E2000.00000002.00000001.01000000.00000024.sdmp, WixHttpExtension.dll.5.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\wix\wix.pdb source: dark.exe, 00000018.00000002.556968676.0000000005592000.00000002.00000001.01000000.0000001D.sdmp, u32.24.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixIIsExtension\WixIIsExtension.pdbt source: dark.exe, 00000018.00000002.556830066.0000000005472000.00000002.00000001.01000000.00000025.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixDifxAppExtension\WixDifxAppExtension.pdb source: dark.exe, dark.exe, 00000018.00000002.556332220.0000000002EA2000.00000002.00000001.01000000.0000001F.sdmp
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\Installer\FWWindowNative\bin\Release\Win32\FWWindowNative.pdb source: FWWindowNative.dll.5.dr
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\FW5DeviceApp\JBusCore.Native\JBusModules\JBM_User\vs12\bin\Release\Win32\JBM_User_vs12.pdb source: u20.24.dr, JBM_User_vs12.dll.5.dr
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\FW5DeviceApp\JBusCore.Native\JBusModules\JBM_SNMP\vs12\bin\Release\Win32\JBM_SNMP_vs12.pdb source: JBM_SNMP_vs12.dll.5.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixFirewallExtension\WixFirewallExtension.pdb source: dark.exe, dark.exe, 00000018.00000002.556468998.0000000002F42000.00000002.00000001.01000000.00000022.sdmp, WixFirewallExtension.dll.5.dr, u36.24.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixDirectXExtension\WixDirectXExtension.pdb source: dark.exe, u35.24.dr
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\FW5DeviceApp\JBusCore.Native\JBusModules\JBM_Resolver\vs12\bin\Release\Win32\JBM_Resolver_vs12.pdb source: JBM_Resolver_vs12.dll.5.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixSqlExtension\WixSqlExtension.pdb source: dark.exe, 00000018.00000002.557417725.0000000005742000.00000002.00000001.01000000.00000027.sdmp
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\winterop.pdb source: dark.exe, 00000018.00000002.559615278.000000006FF45000.00000002.00000001.01000000.0000002B.sdmp, winterop.dll.5.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixUtilExtension\WixUtilExtension.pdb source: dark.exe, 00000018.00000002.557734588.0000000005862000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\FW5DeviceApp\JBusCore.Native\JBusModules\JBM_SNMP\vs12\bin\Release\Win32\JBM_SNMP_vs12.pdbSS source: JBM_SNMP_vs12.dll.5.dr
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\Installer\vs\JBM_RAF_Static\bin\Release\Win32\JBM_RAF_Static.pdb source: JBM_RAF_Static.dll.5.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\wix\wix.pdbh source: dark.exe, 00000018.00000002.556968676.0000000005592000.00000002.00000001.01000000.0000001D.sdmp, u32.24.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixUIExtension\WixUIExtension.pdb source: dark.exe, 00000018.00000002.558081633.0000000005B32000.00000002.00000001.01000000.00000029.sdmp
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_00904440 FindFirstFileW,FindClose,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008F7B87 FindFirstFileExW,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008D9B43 FindFirstFileW,lstrlenW,FindNextFileW,FindClose,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008C3CC4 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,
Source: LMSetup.exeString found in binary or memory: http://appsyndication.org/2006/appsyn
Source: LMSetup.exeString found in binary or memory: http://appsyndication.org/2006/appsynapplicationapuputil.cppupgradeexclusivetrueenclosuredigestalgor
Source: dark.exe, 00000018.00000002.557734588.0000000005862000.00000002.00000001.01000000.00000028.sdmpString found in binary or memory: http://appsyndication.org/schemas/appsyn5rss/channel/as:applicationKDid
Source: LMSetup.exe, 00000005.00000003.406860034.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.407217388.000000000A46F000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.407122395.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.407017293.000000000A46F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://en.wikipqxg
Source: dark.exe, 00000018.00000002.556628591.0000000003085000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://s1.symcb.com/pca3-g5.crl0
Source: dark.exe, 00000018.00000002.556628591.0000000003085000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://s2.symcb.com0
Source: dark.exeString found in binary or memory: http://schemas.m
Source: dark.exeString found in binary or memory: http://schemas.micro
Source: dark.exe, 00000018.00000002.556628591.0000000003085000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: dark.exe, 00000018.00000002.556628591.0000000003085000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://sv.symcb.com/sv.crl0a
Source: dark.exe, 00000018.00000002.556628591.0000000003085000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://sv.symcb.com/sv.crt0
Source: dark.exe, 00000018.00000002.556628591.0000000003085000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://sv.symcd.com0&
Source: dark.exeString found in binary or memory: http://wixtoolset.org
Source: dark.exeString found in binary or memory: http://wixtoolset.org/
Source: dark.exe, 00000018.00000002.558081633.0000000005B32000.00000002.00000001.01000000.00000029.sdmp, dark.exe, 00000018.00000002.556468998.0000000002F42000.00000002.00000001.01000000.00000022.sdmp, dark.exe, 00000018.00000000.486739438.0000000000B02000.00000002.00000001.01000000.0000001C.sdmp, dark.exe, 00000018.00000002.556500646.0000000002F62000.00000002.00000001.01000000.00000023.sdmp, dark.exe, 00000018.00000002.556332220.0000000002EA2000.00000002.00000001.01000000.0000001F.sdmp, dark.exe, 00000018.00000002.559434031.0000000005ED2000.00000002.00000001.01000000.0000002A.sdmp, dark.exe, 00000018.00000002.557417725.0000000005742000.00000002.00000001.01000000.00000027.sdmp, dark.exe, 00000018.00000002.556908564.0000000005532000.00000002.00000001.01000000.00000026.sdmp, dark.exe, 00000018.00000002.556392871.0000000002EF2000.00000002.00000001.01000000.00000020.sdmp, dark.exe, 00000018.00000002.556791687.00000000053E2000.00000002.00000001.01000000.00000024.sdmp, dark.exe, 00000018.00000002.556830066.0000000005472000.00000002.00000001.01000000.00000025.sdmp, dark.exe, 00000018.00000002.557734588.0000000005862000.00000002.00000001.01000000.00000028.sdmp, WixHttpExtension.dll.5.dr, WixFirewallExtension.dll.5.dr, u36.24.dr, u35.24.drString found in binary or memory: http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/v
Source: u32.24.drString found in binary or memory: http://wixtoolset.org/documentation/error217/
Source: dark.exe, dark.exe, 00000018.00000002.558081633.0000000005B32000.00000002.00000001.01000000.00000029.sdmp, dark.exe, 00000018.00000002.556468998.0000000002F42000.00000002.00000001.01000000.00000022.sdmp, dark.exe, 00000018.00000000.486739438.0000000000B02000.00000002.00000001.01000000.0000001C.sdmp, dark.exe, 00000018.00000002.556500646.0000000002F62000.00000002.00000001.01000000.00000023.sdmp, dark.exe, 00000018.00000002.556332220.0000000002EA2000.00000002.00000001.01000000.0000001F.sdmp, dark.exe, 00000018.00000002.559434031.0000000005ED2000.00000002.00000001.01000000.0000002A.sdmp, dark.exe, 00000018.00000002.557417725.0000000005742000.00000002.00000001.01000000.00000027.sdmp, dark.exe, 00000018.00000002.556968676.0000000005592000.00000002.00000001.01000000.0000001D.sdmp, dark.exe, 00000018.00000002.556908564.0000000005532000.00000002.00000001.01000000.00000026.sdmp, dark.exe, 00000018.00000002.556392871.0000000002EF2000.00000002.00000001.01000000.00000020.sdmp, dark.exe, 00000018.00000002.556791687.00000000053E2000.00000002.00000001.01000000.00000024.sdmp, dark.exe, 00000018.00000002.556830066.0000000005472000.00000002.00000001.01000000.00000025.sdmp, dark.exe, 00000018.00000002.557734588.0000000005862000.00000002.00000001.01000000.00000028.sdmp, WixHttpExtension.dll.5.dr, WixFirewallExtension.dll.5.dr, u36.24.dr, u35.24.dr, u32.24.drString found in binary or memory: http://wixtoolset.org/news/
Source: dark.exe, dark.exe, 00000018.00000002.558081633.0000000005B32000.00000002.00000001.01000000.00000029.sdmp, dark.exe, 00000018.00000002.556468998.0000000002F42000.00000002.00000001.01000000.00000022.sdmp, dark.exe, 00000018.00000000.486739438.0000000000B02000.00000002.00000001.01000000.0000001C.sdmp, dark.exe, 00000018.00000002.556500646.0000000002F62000.00000002.00000001.01000000.00000023.sdmp, dark.exe, 00000018.00000002.556332220.0000000002EA2000.00000002.00000001.01000000.0000001F.sdmp, dark.exe, 00000018.00000002.556392871.0000000002EF2000.00000002.00000001.01000000.00000020.sdmp, dark.exe, 00000018.00000002.557734588.0000000005862000.00000002.00000001.01000000.00000028.sdmp, WixFirewallExtension.dll.5.dr, u36.24.dr, u35.24.drString found in binary or memory: http://wixtoolset.org/releases/
Source: dark.exeString found in binary or memory: http://wixtoolset.org/releases/feed/v3.11
Source: dark.exe, 00000018.00000002.559434031.0000000005ED2000.00000002.00000001.01000000.0000002A.sdmpString found in binary or memory: http://wixtoolset.org/releases/sMicrosoft.Tools.WindowsInstallerXml.Extensions.Xsd.vs.xsd
Source: dark.exe, 00000018.00000002.556830066.0000000005472000.00000002.00000001.01000000.00000025.sdmpString found in binary or memory: http://wixtoolset.org/releases/uMicrosoft.Tools.WindowsInstallerXml.Extensions.Xsd.iis.xsd
Source: dark.exe, 00000018.00000002.557417725.0000000005742000.00000002.00000001.01000000.00000027.sdmpString found in binary or memory: http://wixtoolset.org/releases/uMicrosoft.Tools.WindowsInstallerXml.Extensions.Xsd.sql.xsd
Source: dark.exe, 00000018.00000002.556791687.00000000053E2000.00000002.00000001.01000000.00000024.sdmp, WixHttpExtension.dll.5.drString found in binary or memory: http://wixtoolset.org/releases/wMicrosoft.Tools.WindowsInstallerXml.Extensions.Xsd.http.xsd
Source: dark.exe, 00000018.00000002.556908564.0000000005532000.00000002.00000001.01000000.00000026.sdmpString found in binary or memory: http://wixtoolset.org/releases/yMicrosoft.Tools.WindowsInstallerXml.Extensions.Xsd.netfx.xsd
Source: dark.exeString found in binary or memory: http://wixtoolset.org/telemetry/v
Source: LMSetup.exe, 00000005.00000003.410864207.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: LMSetup.exe, 00000005.00000003.429990990.0000000005323000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com
Source: LMSetup.exe, 00000005.00000003.425385234.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.431133719.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.446818415.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.430983857.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.446748903.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.431274097.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.446576344.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.430825935.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.424486510.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.446492562.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.425763015.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.446371295.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.426162319.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.446234440.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.425962737.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers
Source: LMSetup.exe, 00000005.00000003.425570469.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.426981530.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers)
Source: LMSetup.exe, 00000005.00000003.424339254.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.424486510.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/
Source: LMSetup.exe, 00000005.00000003.428860600.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.html
Source: LMSetup.exe, 00000005.00000003.429383019.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.428860600.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.429182478.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.429027170.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlD
Source: LMSetup.exe, 00000005.00000003.426859603.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.426981530.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.427118337.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-jones.htmloW~
Source: LMSetup.exe, 00000005.00000003.429383019.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers2
Source: LMSetup.exe, 00000005.00000003.429567950.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers:
Source: LMSetup.exe, 00000005.00000003.430983857.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.430825935.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers?
Source: LMSetup.exe, 00000005.00000003.431133719.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersA
Source: LMSetup.exe, 00000005.00000003.424621358.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersDC
Source: LMSetup.exe, 00000005.00000003.429567950.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersJ
Source: LMSetup.exe, 00000005.00000003.446371295.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersS
Source: LMSetup.exe, 00000005.00000003.446234440.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersUK
Source: LMSetup.exe, 00000005.00000003.431133719.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.431274097.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersb
Source: LMSetup.exe, 00000005.00000003.424621358.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.424738869.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.424486510.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersd
Source: LMSetup.exe, 00000005.00000003.425763015.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.426162319.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.425962737.000000000A46B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersl1
Source: LMSetup.exe, 00000005.00000003.429990990.0000000005323000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comalsFT
Source: LMSetup.exe, 00000005.00000003.429990990.0000000005323000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comitudi
Source: LMSetup.exe, 00000005.00000003.428643198.0000000005323000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comp
Source: dark.exe, 00000018.00000002.556628591.0000000003085000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.symauth.com/cps0(
Source: dark.exe, 00000018.00000002.556628591.0000000003085000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.symauth.com/rpa00
Source: dark.exe, 00000018.00000002.556628591.0000000003085000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://d.symcb.com/cps0%
Source: dark.exe, 00000018.00000002.556628591.0000000003085000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://d.symcb.com/rpa0
Source: dark.exe, 00000018.00000002.555816779.000000000129B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>
Source: LMSetup.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: C:\Users\user\Desktop\LMSetup.exeFile created: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\Jump to behavior
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008F001D
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008E41EA
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008C62AA
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008F03D5
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008EC332
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008FA560
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008F07AA
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008CA8F1
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008FAA0E
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008EFB89
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008F0B6F
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008F2C18
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008F2E47
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008FEE7C
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A2FF437
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A302A12
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A2FBC12
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A301070
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A302C7A
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A308455
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A2FF2B7
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A305493
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A305CD3
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A308537
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A2FA93B
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A2FE173
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A300FBA
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A2FFFBB
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A2F3186
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A30239A
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A2FD1FA
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A3033D7
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A303FC1
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A303A24
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A2FED17
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A2FD05A
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeCode function: 24_2_02EF407F
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeCode function: 24_2_02EF42F6
Source: C:\Users\user\Desktop\LMSetup.exeCode function: String function: 008C1F13 appears 54 times
Source: C:\Users\user\Desktop\LMSetup.exeCode function: String function: 00900237 appears 683 times
Source: C:\Users\user\Desktop\LMSetup.exeCode function: String function: 008C3821 appears 501 times
Source: C:\Users\user\Desktop\LMSetup.exeCode function: String function: 00900726 appears 34 times
Source: C:\Users\user\Desktop\LMSetup.exeCode function: String function: 009032F3 appears 83 times
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess Stats: CPU usage > 98%
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE
Source: LMSetup.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: LMSetup.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: LMSetup.exe.0.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: LMSetup.exe.0.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: WixDependencyExtension.dll.5.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: WixDirectXExtension.dll.5.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: WixFirewallExtension.dll.5.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: WixGamingExtension.dll.5.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: WixHttpExtension.dll.5.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: WixSqlExtension.dll.5.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\LMSetup.exeFile read: C:\Users\user\Desktop\LMSetup.exeJump to behavior
Source: LMSetup.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\LMSetup.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknownProcess created: C:\Users\user\Desktop\LMSetup.exe "C:\Users\user\Desktop\LMSetup.exe"
Source: C:\Users\user\Desktop\LMSetup.exeProcess created: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe "C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe" -burn.clean.room="C:\Users\user\Desktop\LMSetup.exe" -burn.filehandle.attached=556 -burn.filehandle.self=576
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd" /c C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe "C:\Users\user\Desktop\LMSetup.exe" -nologo -x "C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe "C:\Users\user\Desktop\LMSetup.exe" -nologo -x "C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba"
Source: C:\Users\user\Desktop\LMSetup.exeProcess created: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe "C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe" -burn.clean.room="C:\Users\user\Desktop\LMSetup.exe" -burn.filehandle.attached=556 -burn.filehandle.self=576
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd" /c C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe "C:\Users\user\Desktop\LMSetup.exe" -nologo -x "C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe "C:\Users\user\Desktop\LMSetup.exe" -nologo -x "C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba"
Source: C:\Users\user\Desktop\LMSetup.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InProcServer32
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008C45EE GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle,
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Users\user\AppData\Local\Lenovo\Jump to behavior
Source: C:\Users\user\Desktop\LMSetup.exeFile created: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\Jump to behavior
Source: classification engineClassification label: clean10.evad.winEXE@8/221@0/0
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_0090304F GetModuleHandleA,GetLastError,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CoCreateInstance,ExitProcess,
Source: WixUtilExtension.dll.5.dr, Microsoft.Tools.WindowsInstallerXml/Extensions/PayloadHarvester.csSuspicious method names: Microsoft.Tools.WindowsInstallerXml.Serialize.Fragment[] Microsoft.Tools.WindowsInstallerXml.Extensions.PayloadHarvester::Harvest(System.String)
Source: WixUtilExtension.dll.5.dr, Microsoft.Tools.WindowsInstallerXml/Extensions/PayloadHarvester.csSuspicious method names: System.Void Microsoft.Tools.WindowsInstallerXml.Extensions.PayloadHarvester::.ctor()
Source: WixUtilExtension.dll.5.dr, Microsoft.Tools.WindowsInstallerXml/Extensions/PayloadHarvester.csSuspicious method names: System.Void Microsoft.Tools.WindowsInstallerXml.Extensions.PayloadHarvester::set_SetUniqueIdentifiers(System.Boolean)
Source: WixUtilExtension.dll.5.dr, Microsoft.Tools.WindowsInstallerXml/Extensions/PayloadHarvester.csSuspicious method names: System.Boolean Microsoft.Tools.WindowsInstallerXml.Extensions.PayloadHarvester::get_SetUniqueIdentifiers()
Source: WixUtilExtension.dll.5.dr, Microsoft.Tools.WindowsInstallerXml/Extensions/PayloadHarvester.csSuspicious method names: Microsoft.Tools.WindowsInstallerXml.Serialize.RemotePayload Microsoft.Tools.WindowsInstallerXml.Extensions.PayloadHarvester::HarvestRemotePayload(System.String)
Source: WixVSExtension.dll.5.dr, Microsoft.Tools.WindowsInstallerXml/Extensions/VSProjectHarvester.csSuspicious method names: System.Void Microsoft.Tools.WindowsInstallerXml.Extensions.VSProjectHarvester::HarvestProjectOutputGroupPayloadFile(System.String,System.String,System.String,System.String,System.String,System.String,System.String,Microsoft.Tools.WindowsInstallerXml.Serialize.IParentElement,Microsoft.Tools.WindowsInstallerXml.Serialize.Payload,System.Collections.Generic.Dictionary`2<System.String,System.Boolean>)
Source: dark.exe, 00000018.00000002.556968676.0000000005592000.00000002.00000001.01000000.0000001D.sdmp, u32.24.drBinary or memory string: SELECT `Component_` FROM `FeatureComponents` WHERE `Feature_` = ?iSELECT `FileSize` FROM `File` WHERE `Component_` = ?/SELECT * FROM `Feature`;SELECT `Cabinet` FROM `Media`
Source: WixGamingExtension.dll.5.dr, Tools.WindowsInstallerXml/Extensions/GamingCompiler.csTask registration methods: 'CreateTaskDirectoryRow', 'CreateTaskRootDirectoryCustomActions'
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008FFE21 FormatMessageW,GetLastError,LocalFree,
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008E6B88 ChangeServiceConfigW,GetLastError,
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2944:120:WilError_01
Source: C:\Users\user\Desktop\LMSetup.exeCommand line argument: cabinet.dll
Source: C:\Users\user\Desktop\LMSetup.exeCommand line argument: msi.dll
Source: C:\Users\user\Desktop\LMSetup.exeCommand line argument: version.dll
Source: C:\Users\user\Desktop\LMSetup.exeCommand line argument: wininet.dll
Source: C:\Users\user\Desktop\LMSetup.exeCommand line argument: comres.dll
Source: C:\Users\user\Desktop\LMSetup.exeCommand line argument: clbcatq.dll
Source: C:\Users\user\Desktop\LMSetup.exeCommand line argument: msasn1.dll
Source: C:\Users\user\Desktop\LMSetup.exeCommand line argument: crypt32.dll
Source: C:\Users\user\Desktop\LMSetup.exeCommand line argument: feclient.dll
Source: C:\Users\user\Desktop\LMSetup.exeCommand line argument: cabinet.dll
Source: LMSetup.exeString found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: dark.exeString found in binary or memory: ath> -xo output wixout instead of WiX source code (mandatory for transforms and patches) -? | -help this help information Environment variables: WIX_TEMP overrides the temporary directory used for cab extraction, binary e
Source: dark.exeString found in binary or memory: b\DependencyExtension_x86.wxs*7"><field>WixAction</field><field>InstallExecuteSequence/InstallInitialize</field></row><row sourceLineNumber="C:\agent\_work\8\s\src\ext\DependencyExtension\wixlib\DependencyExtension_Platform.wxi*20|C:\agent\_work\8\s\src\ext\De
Source: dark.exeString found in binary or memory: lib\DirectXExtension.wxs*17"><field>CustomAction</field><field>WixQueryDirectXCaps</field></row><row sourceLineNumber="C:\agent\_work\8\s\src\ext\DirectXExtension\wixlib\DirectXExtension.wxs*17"><field>WixAction</field><field>InstallUISequence/LaunchConditions
Source: dark.exeString found in binary or memory: xtension.wxs*21"><field>WixAction</field><field>InstallExecuteSequence/LaunchConditions</field></row></table></section><section type="fragment" xmlns="http://schemas.microsoft.com/wix/2006/objects"><table name="Property"><row sourceLineNumber="C:\agent\_work\8
Source: LMSetup.exeString found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: LMSetup.exeString found in binary or memory: InstallerPackages/installer/installer.zipd
Source: LMSetup.exeString found in binary or memory: )InstallerPackages/installer/installer.zipd
Source: LMSetup.exeStatic file information: File size 49224728 > 1048576
Source: LMSetup.exeStatic PE information: certificate valid
Source: LMSetup.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: LMSetup.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: LMSetup.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: LMSetup.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: LMSetup.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: LMSetup.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: LMSetup.exeStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: LMSetup.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\DependencyExtension\WixDependencyExtension.pdb source: dark.exe, dark.exe, 00000018.00000002.556392871.0000000002EF2000.00000002.00000001.01000000.00000020.sdmp
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\burn.pdb source: LMSetup.exe
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixUtilExtension\WixUtilExtension.pdb| source: dark.exe, 00000018.00000002.557734588.0000000005862000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixIIsExtension\WixIIsExtension.pdb source: dark.exe, 00000018.00000002.556830066.0000000005472000.00000002.00000001.01000000.00000025.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixVSExtension\WixVSExtension.pdb source: dark.exe, 00000018.00000002.559434031.0000000005ED2000.00000002.00000001.01000000.0000002A.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixGamingExtension\WixGamingExtension.pdb source: dark.exe, 00000018.00000002.556500646.0000000002F62000.00000002.00000001.01000000.00000023.sdmp
Source: Binary string: pdbaMicrosoft.Tools.WindowsInstallerXml.Xsd.pdbs.xsdUhttp://schemas.microsoft.com/wix/2006/pdbs source: dark.exe, 00000018.00000002.556968676.0000000005592000.00000002.00000001.01000000.0000001D.sdmp, u32.24.dr
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\FW5DeviceApp\JBusCore.Native\JBusModules\JBM_Resolver\vs12\bin\Release\Win32\JBM_Resolver_vs12.pdb,, source: JBM_Resolver_vs12.dll.5.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixUIExtension\WixUIExtension.pdbL source: dark.exe, 00000018.00000002.558081633.0000000005B32000.00000002.00000001.01000000.00000029.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixGamingExtension\WixGamingExtension.pdb( source: dark.exe, 00000018.00000002.556500646.0000000002F62000.00000002.00000001.01000000.00000023.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\dark\dark.pdb source: dark.exe, dark.exe, 00000018.00000000.486739438.0000000000B02000.00000002.00000001.01000000.0000001C.sdmp
Source: Binary string: Microsoft.Tools.WindowsInstallerXml.Xsd.pdbs.xsd source: dark.exe, 00000018.00000002.556968676.0000000005592000.00000002.00000001.01000000.0000001D.sdmp, u32.24.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixNetfxExtension\WixNetFxExtension.pdb source: dark.exe, 00000018.00000002.556908564.0000000005532000.00000002.00000001.01000000.00000026.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixHttpExtension\WixHttpExtension.pdb source: dark.exe, 00000018.00000002.556791687.00000000053E2000.00000002.00000001.01000000.00000024.sdmp, WixHttpExtension.dll.5.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\wix\wix.pdb source: dark.exe, 00000018.00000002.556968676.0000000005592000.00000002.00000001.01000000.0000001D.sdmp, u32.24.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixIIsExtension\WixIIsExtension.pdbt source: dark.exe, 00000018.00000002.556830066.0000000005472000.00000002.00000001.01000000.00000025.sdmp
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixDifxAppExtension\WixDifxAppExtension.pdb source: dark.exe, dark.exe, 00000018.00000002.556332220.0000000002EA2000.00000002.00000001.01000000.0000001F.sdmp
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\Installer\FWWindowNative\bin\Release\Win32\FWWindowNative.pdb source: FWWindowNative.dll.5.dr
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\FW5DeviceApp\JBusCore.Native\JBusModules\JBM_User\vs12\bin\Release\Win32\JBM_User_vs12.pdb source: u20.24.dr, JBM_User_vs12.dll.5.dr
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\FW5DeviceApp\JBusCore.Native\JBusModules\JBM_SNMP\vs12\bin\Release\Win32\JBM_SNMP_vs12.pdb source: JBM_SNMP_vs12.dll.5.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixFirewallExtension\WixFirewallExtension.pdb source: dark.exe, dark.exe, 00000018.00000002.556468998.0000000002F42000.00000002.00000001.01000000.00000022.sdmp, WixFirewallExtension.dll.5.dr, u36.24.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixDirectXExtension\WixDirectXExtension.pdb source: dark.exe, u35.24.dr
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\FW5DeviceApp\JBusCore.Native\JBusModules\JBM_Resolver\vs12\bin\Release\Win32\JBM_Resolver_vs12.pdb source: JBM_Resolver_vs12.dll.5.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixSqlExtension\WixSqlExtension.pdb source: dark.exe, 00000018.00000002.557417725.0000000005742000.00000002.00000001.01000000.00000027.sdmp
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\winterop.pdb source: dark.exe, 00000018.00000002.559615278.000000006FF45000.00000002.00000001.01000000.0000002B.sdmp, winterop.dll.5.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixUtilExtension\WixUtilExtension.pdb source: dark.exe, 00000018.00000002.557734588.0000000005862000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\FW5DeviceApp\JBusCore.Native\JBusModules\JBM_SNMP\vs12\bin\Release\Win32\JBM_SNMP_vs12.pdbSS source: JBM_SNMP_vs12.dll.5.dr
Source: Binary string: C:\jenkins\workspace\funnelweb10\funnelweb10_vs2017\Installer\vs\JBM_RAF_Static\bin\Release\Win32\JBM_RAF_Static.pdb source: JBM_RAF_Static.dll.5.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\wix\wix.pdbh source: dark.exe, 00000018.00000002.556968676.0000000005592000.00000002.00000001.01000000.0000001D.sdmp, u32.24.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WixUIExtension\WixUIExtension.pdb source: dark.exe, 00000018.00000002.558081633.0000000005B32000.00000002.00000001.01000000.00000029.sdmp
Source: LMSetup.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: LMSetup.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: LMSetup.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: LMSetup.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: LMSetup.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008EEAD6 push ecx; ret
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeCode function: 5_3_0A2F9002 push eax; ret
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeCode function: 24_2_02EA5360 push ecx; iretd
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeCode function: 24_2_02F0A4A3 push esi; ret
Source: LMSetup.exeStatic PE information: section name: .wixburn
Source: LMSetup.exe.0.drStatic PE information: section name: .wixburn
Source: vccorlib110.dll.5.drStatic PE information: section name: minATL
Source: initial sampleStatic PE information: section name: .text entropy: 6.92420163356
Source: initial sampleStatic PE information: section name: .text entropy: 7.38047865037
Source: initial sampleStatic PE information: section name: .text entropy: 7.81678730261
Source: initial sampleStatic PE information: section name: .text entropy: 7.52939429346
Source: initial sampleStatic PE information: section name: .text entropy: 7.60824281471
Source: initial sampleStatic PE information: section name: .text entropy: 7.58506941708
Source: initial sampleStatic PE information: section name: .text entropy: 7.49615358644
Source: initial sampleStatic PE information: section name: .text entropy: 7.83645052643
Source: initial sampleStatic PE information: section name: .text entropy: 7.44554243282
Source: initial sampleStatic PE information: section name: .text entropy: 7.59436656349
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u17
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u18
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u19
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u20
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u21
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u22
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u23
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u28
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u30
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u31
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u32
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u33
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u34
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u35
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u36
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u37
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u38
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u39
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u40
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u41
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u42
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u43
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u44
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u0
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u2
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u5
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u6
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u7
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u9
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u10
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u11
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u12
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u13
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u14
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u15
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u16
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u36
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u37
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u7
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u38
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u6
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\FWWindowNative.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u39
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u5
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u32
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u33
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_StateMachine_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u34
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u2
Source: C:\Users\user\Desktop\LMSetup.exeFile created: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixDifxAppExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u35
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_InstallerUtils_Static.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u9
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_AppConfig_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_User_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\FW5FWSDK_Net45_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_Resolver_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_PluginCache_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u30
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u31
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixUtilExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixFirewallExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u28
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u21
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u22
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u23
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_SNMP_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixDirectXExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\msvcr110.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\msvcp110.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixIIsExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\vccorlib110.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixDependencyExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u20
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_System_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u14
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_RAF_Static.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u15
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u16
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixGamingExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u17
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u10
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u11
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u12
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u13
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u18
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\wix.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u19
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\TAPToaster.exe
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixVSExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixSqlExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\winterop.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_Propertybag_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixHttpExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_Encryption_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixUIExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_Locale_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixNetFxExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u43
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u44
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\TAPInstallerNative.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\FW5JCore_vs12_x86.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_WixInstaller_Static.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u0
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u40
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u41
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u42
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u36
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u37
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u7
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u38
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u6
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\FWWindowNative.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u39
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u5
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u32
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u33
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_StateMachine_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u34
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u2
Source: C:\Users\user\Desktop\LMSetup.exeFile created: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixDifxAppExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u35
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_InstallerUtils_Static.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u9
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_AppConfig_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_User_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\FW5FWSDK_Net45_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_Resolver_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_PluginCache_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u30
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u31
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixUtilExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixFirewallExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u28
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u21
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u22
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u23
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_SNMP_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixDirectXExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\msvcr110.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\msvcp110.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixIIsExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\vccorlib110.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixDependencyExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u20
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_System_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u14
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_RAF_Static.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u15
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u16
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixGamingExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u17
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u10
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u11
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u12
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u13
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u18
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\wix.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u19
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\TAPToaster.exe
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixVSExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixSqlExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\winterop.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_Propertybag_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixHttpExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_Encryption_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixUIExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_Locale_vs12.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixNetFxExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u43
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u44
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\TAPInstallerNative.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\FW5JCore_vs12_x86.dllJump to dropped file
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\JBM_WixInstaller_Static.dllJump to dropped file
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u0
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u40
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u41
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u42
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\cs\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\da\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\de-de\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\el\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\en-gb\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\en-us\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\es-es\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\fi\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\fr-fr\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\hu\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\it-it\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\ja\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\nl-nl\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\no-no\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\pl\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\pt-br\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\pt-pt\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\ru\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\sv-se\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\tr-tr\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\zh-cn\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\License\zh-tw\license.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\cs\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\da\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\de-de\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\en-gb\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\en-us\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\es-es\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\fi\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\fr-fr\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\hu\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\it-it\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\ja\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\nl-nl\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\no-no\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\pl\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\pt-br\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\pt-pt\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\ru\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\sv-se\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\tr-tr\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\zh-cn\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeFile created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\Readme\zh-tw\readme.txtJump to behavior
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u36
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u37
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u7
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u38
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u6
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u39
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u5
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u32
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u33
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u34
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u35
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixDifxAppExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u9
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u30
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u31
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixUtilExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixFirewallExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u28
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u21
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u22
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u23
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixDirectXExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixIIsExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\vccorlib110.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u20
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixDependencyExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u14
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u15
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u16
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixGamingExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u17
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u10
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u11
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u12
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u13
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u18
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\wix.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u19
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\TAPToaster.exe
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixVSExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixSqlExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixHttpExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixUIExtension.dll
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixNetFxExtension.dll
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u43
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u44
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u0
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u40
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u41
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeDropped PE file which has not been started: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\UX\u42
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008FFEC6 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 008FFF61h
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008FFEC6 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 008FFF5Ah
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeRegistry key enumerated: More than 151 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeMemory allocated: 4750000 memory reserve | memory write watch
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeMemory allocated: 3B50000 memory reserve | memory write watch
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeMemory allocated: 53D0000 memory commit | memory reserve | memory write watch
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeMemory allocated: 5550000 memory commit | memory reserve | memory write watch
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeMemory allocated: 5570000 memory commit | memory reserve | memory write watch
Source: C:\Users\user\Desktop\LMSetup.exeCheck user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\LMSetup.exeAPI coverage: 10.0 %
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_ComputerSystem
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess information queried: ProcessInformation
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_009097A5 VirtualQuery,GetSystemInfo,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_00904440 FindFirstFileW,FindClose,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008F7B87 FindFirstFileExW,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008D9B43 FindFirstFileW,lstrlenW,FindNextFileW,FindClose,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008C3CC4 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,
Source: C:\Users\user\Desktop\LMSetup.exeAPI call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008EE88A IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008C394F GetProcessHeap,RtlAllocateHeap,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008F48D8 mov eax, dword ptr fs:[00000030h]
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeMemory allocated: page read and write | page guard
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008EE9DC SetUnhandledExceptionFilter,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008EE3D8 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008EE88A IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008F3C76 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,
Source: C:\Users\user\Desktop\LMSetup.exeProcess created: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe "C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe" -burn.clean.room="C:\Users\user\Desktop\LMSetup.exe" -burn.filehandle.attached=556 -burn.filehandle.self=576
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd" /c C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe "C:\Users\user\Desktop\LMSetup.exe" -nologo -x "C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe "C:\Users\user\Desktop\LMSetup.exe" -nologo -x "C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba"
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_00901719 InitializeSecurityDescriptor,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,GetLastError,CreateWellKnownSid,GetLastError,CreateWellKnownSid,GetLastError,CreateWellKnownSid,GetLastError,SetEntriesInAclA,SetSecurityDescriptorOwner,GetLastError,SetSecurityDescriptorGroup,GetLastError,SetSecurityDescriptorDacl,GetLastError,CoInitializeSecurity,LocalFree,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_00903A5F AllocateAndInitializeSid,CheckTokenMembership,
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ARIALN.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ariali.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ARIALNI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ARIALNB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ARIALNBI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ariblk.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\calibril.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\calibri.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\consola.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\consolai.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\consolab.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\consolaz.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\seguiemj.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\marlett.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
Source: C:\Windows\SysWOW64\cmd.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\wix.dll VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixDifxAppExtension.dll VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixDependencyExtension.dll VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixDirectXExtension.dll VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixFirewallExtension.dll VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixGamingExtension.dll VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixHttpExtension.dll VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixIIsExtension.dll VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixNetFxExtension.dll VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixSqlExtension.dll VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixUIExtension.dll VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixUtilExtension.dll VolumeInformation
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeQueries volume information: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\WixVSExtension.dll VolumeInformation
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008EEC07 cpuid
Source: C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008D4EDF ConvertStringSecurityDescriptorToSecurityDescriptorW,GetLastError,CreateNamedPipeW,GetLastError,CreateNamedPipeW,GetLastError,CloseHandle,LocalFree,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008C6037 GetSystemTime,GetDateFormatW,GetLastError,GetLastError,GetDateFormatW,GetLastError,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_0090887B GetTimeZoneInformation,SystemTimeToTzSpecificLocalTime,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008C5195 GetModuleHandleW,CoInitializeEx,GetVersionExW,GetLastError,CoUninitialize,
Source: C:\Users\user\Desktop\LMSetup.exeCode function: 0_2_008C61DF GetUserNameW,GetLastError,
Source: C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exeRegistry value created: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_NINPUT_LEGACYMODEJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts21
Windows Management Instrumentation
1
Windows Service
1
Access Token Manipulation
1
Disable or Modify Tools
1
Input Capture
12
System Time Discovery
Remote Services1
Archive Collected Data
Exfiltration Over Other Network Medium2
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default Accounts1
Native API
1
Scheduled Task/Job
1
Windows Service
1
Deobfuscate/Decode Files or Information
LSASS Memory1
Account Discovery
Remote Desktop Protocol1
Email Collection
Exfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain Accounts3
Command and Scripting Interpreter
Logon Script (Windows)12
Process Injection
3
Obfuscated Files or Information
Security Account Manager1
File and Directory Discovery
SMB/Windows Admin Shares1
Input Capture
Automated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local Accounts1
Scheduled Task/Job
Logon Script (Mac)1
Scheduled Task/Job
2
Software Packing
NTDS46
System Information Discovery
Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud Accounts1
Service Execution
Network Logon ScriptNetwork Logon Script31
Masquerading
LSA Secrets4
Security Software Discovery
SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.common31
Virtualization/Sandbox Evasion
Cached Domain Credentials31
Virtualization/Sandbox Evasion
VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
External Remote ServicesScheduled TaskStartup ItemsStartup Items1
Modify Registry
DCSync11
Process Discovery
Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/Job1
Access Token Manipulation
Proc Filesystem1
System Owner/User Discovery
Shared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)12
Process Injection
/etc/passwd and /etc/shadowSystem Network Connections DiscoverySoftware Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 562516 Sample: LMSetup.exe Startdate: 28/01/2022 Architecture: WINDOWS Score: 10 7 LMSetup.exe 3 2->7         started        file3 20 C:\Windows\Temp\...\LMSetup.exe, PE32 7->20 dropped 10 LMSetup.exe 5 311 7->10         started        process4 file5 22 C:\Windows\Temp\...\wix.dll, PE32 10->22 dropped 24 C:\Windows\Temp\...\winterop.dll, PE32 10->24 dropped 26 C:\Windows\Temp\...\vccorlib110.dll, PE32 10->26 dropped 28 33 other files (none is malicious) 10->28 dropped 13 cmd.exe 1 10->13         started        process6 process7 15 dark.exe 92 13->15         started        18 conhost.exe 13->18         started        file8 30 C:\Windows\Temp\...\u9, PE32 15->30 dropped 32 C:\Windows\Temp\...\u7, PE32 15->32 dropped 34 C:\Windows\Temp\...\u6, PE32 15->34 dropped 36 33 other files (none is malicious) 15->36 dropped

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://schemas.m0%URL Reputationsafe
http://appsyndication.org/2006/appsynapplicationapuputil.cppupgradeexclusivetrueenclosuredigestalgor0%URL Reputationsafe
http://schemas.micro0%URL Reputationsafe
http://www.fontbureau.comitudi0%Avira URL Cloudsafe
http://appsyndication.org/schemas/appsyn5rss/channel/as:applicationKDid0%Avira URL Cloudsafe
http://www.fontbureau.comp0%Avira URL Cloudsafe
http://en.wikipqxg0%Avira URL Cloudsafe
http://appsyndication.org/2006/appsyn0%URL Reputationsafe
http://www.fontbureau.comalsFT0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.apache.org/licenses/LICENSE-2.0LMSetup.exe, 00000005.00000003.410864207.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
    high
    http://www.fontbureau.comLMSetup.exe, 00000005.00000003.429990990.0000000005323000.00000004.00000800.00020000.00000000.sdmpfalse
      high
      http://schemas.mdark.exefalse
      • URL Reputation: safe
      unknown
      http://www.fontbureau.com/designersJLMSetup.exe, 00000005.00000003.429567950.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
        high
        http://wixtoolset.org/releases/feed/v3.11dark.exefalse
          high
          http://www.fontbureau.com/designersALMSetup.exe, 00000005.00000003.431133719.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
            high
            http://www.fontbureau.com/designers?LMSetup.exe, 00000005.00000003.430983857.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.430825935.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
              high
              http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/vdark.exe, 00000018.00000002.558081633.0000000005B32000.00000002.00000001.01000000.00000029.sdmp, dark.exe, 00000018.00000002.556468998.0000000002F42000.00000002.00000001.01000000.00000022.sdmp, dark.exe, 00000018.00000000.486739438.0000000000B02000.00000002.00000001.01000000.0000001C.sdmp, dark.exe, 00000018.00000002.556500646.0000000002F62000.00000002.00000001.01000000.00000023.sdmp, dark.exe, 00000018.00000002.556332220.0000000002EA2000.00000002.00000001.01000000.0000001F.sdmp, dark.exe, 00000018.00000002.559434031.0000000005ED2000.00000002.00000001.01000000.0000002A.sdmp, dark.exe, 00000018.00000002.557417725.0000000005742000.00000002.00000001.01000000.00000027.sdmp, dark.exe, 00000018.00000002.556908564.0000000005532000.00000002.00000001.01000000.00000026.sdmp, dark.exe, 00000018.00000002.556392871.0000000002EF2000.00000002.00000001.01000000.00000020.sdmp, dark.exe, 00000018.00000002.556791687.00000000053E2000.00000002.00000001.01000000.00000024.sdmp, dark.exe, 00000018.00000002.556830066.0000000005472000.00000002.00000001.01000000.00000025.sdmp, dark.exe, 00000018.00000002.557734588.0000000005862000.00000002.00000001.01000000.00000028.sdmp, WixHttpExtension.dll.5.dr, WixFirewallExtension.dll.5.dr, u36.24.dr, u35.24.drfalse
                high
                http://www.fontbureau.com/designersLMSetup.exe, 00000005.00000003.425385234.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.431133719.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.446818415.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.430983857.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.446748903.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.431274097.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.446576344.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.430825935.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.424486510.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.446492562.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.425763015.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.446371295.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.426162319.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.446234440.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.425962737.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                  high
                  http://appsyndication.org/2006/appsynapplicationapuputil.cppupgradeexclusivetrueenclosuredigestalgorLMSetup.exefalse
                  • URL Reputation: safe
                  unknown
                  http://www.fontbureau.com/designersDCLMSetup.exe, 00000005.00000003.424621358.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                    high
                    http://wixtoolset.org/news/dark.exe, dark.exe, 00000018.00000002.558081633.0000000005B32000.00000002.00000001.01000000.00000029.sdmp, dark.exe, 00000018.00000002.556468998.0000000002F42000.00000002.00000001.01000000.00000022.sdmp, dark.exe, 00000018.00000000.486739438.0000000000B02000.00000002.00000001.01000000.0000001C.sdmp, dark.exe, 00000018.00000002.556500646.0000000002F62000.00000002.00000001.01000000.00000023.sdmp, dark.exe, 00000018.00000002.556332220.0000000002EA2000.00000002.00000001.01000000.0000001F.sdmp, dark.exe, 00000018.00000002.559434031.0000000005ED2000.00000002.00000001.01000000.0000002A.sdmp, dark.exe, 00000018.00000002.557417725.0000000005742000.00000002.00000001.01000000.00000027.sdmp, dark.exe, 00000018.00000002.556968676.0000000005592000.00000002.00000001.01000000.0000001D.sdmp, dark.exe, 00000018.00000002.556908564.0000000005532000.00000002.00000001.01000000.00000026.sdmp, dark.exe, 00000018.00000002.556392871.0000000002EF2000.00000002.00000001.01000000.00000020.sdmp, dark.exe, 00000018.00000002.556791687.00000000053E2000.00000002.00000001.01000000.00000024.sdmp, dark.exe, 00000018.00000002.556830066.0000000005472000.00000002.00000001.01000000.00000025.sdmp, dark.exe, 00000018.00000002.557734588.0000000005862000.00000002.00000001.01000000.00000028.sdmp, WixHttpExtension.dll.5.dr, WixFirewallExtension.dll.5.dr, u36.24.dr, u35.24.dr, u32.24.drfalse
                      high
                      http://schemas.microdark.exefalse
                      • URL Reputation: safe
                      unknown
                      http://wixtoolset.org/releases/yMicrosoft.Tools.WindowsInstallerXml.Extensions.Xsd.netfx.xsddark.exe, 00000018.00000002.556908564.0000000005532000.00000002.00000001.01000000.00000026.sdmpfalse
                        high
                        http://www.symauth.com/cps0(dark.exe, 00000018.00000002.556628591.0000000003085000.00000004.00000800.00020000.00000000.sdmpfalse
                          high
                          http://www.fontbureau.com/designersSLMSetup.exe, 00000005.00000003.446371295.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                            high
                            http://www.fontbureau.com/designers)LMSetup.exe, 00000005.00000003.425570469.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.426981530.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              http://www.fontbureau.com/designers/frere-jones.htmloW~LMSetup.exe, 00000005.00000003.426859603.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.426981530.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.427118337.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                                high
                                http://wixtoolset.org/releases/dark.exe, dark.exe, 00000018.00000002.558081633.0000000005B32000.00000002.00000001.01000000.00000029.sdmp, dark.exe, 00000018.00000002.556468998.0000000002F42000.00000002.00000001.01000000.00000022.sdmp, dark.exe, 00000018.00000000.486739438.0000000000B02000.00000002.00000001.01000000.0000001C.sdmp, dark.exe, 00000018.00000002.556500646.0000000002F62000.00000002.00000001.01000000.00000023.sdmp, dark.exe, 00000018.00000002.556332220.0000000002EA2000.00000002.00000001.01000000.0000001F.sdmp, dark.exe, 00000018.00000002.556392871.0000000002EF2000.00000002.00000001.01000000.00000020.sdmp, dark.exe, 00000018.00000002.557734588.0000000005862000.00000002.00000001.01000000.00000028.sdmp, WixFirewallExtension.dll.5.dr, u36.24.dr, u35.24.drfalse
                                  high
                                  http://wixtoolset.org/releases/uMicrosoft.Tools.WindowsInstallerXml.Extensions.Xsd.iis.xsddark.exe, 00000018.00000002.556830066.0000000005472000.00000002.00000001.01000000.00000025.sdmpfalse
                                    high
                                    http://wixtoolset.orgdark.exefalse
                                      high
                                      http://www.fontbureau.com/designers/cabarga.htmlLMSetup.exe, 00000005.00000003.428860600.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                                        high
                                        http://www.fontbureau.com/designersl1LMSetup.exe, 00000005.00000003.425763015.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.426162319.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.425962737.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                                          high
                                          http://www.fontbureau.comitudiLMSetup.exe, 00000005.00000003.429990990.0000000005323000.00000004.00000800.00020000.00000000.sdmpfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          http://www.symauth.com/rpa00dark.exe, 00000018.00000002.556628591.0000000003085000.00000004.00000800.00020000.00000000.sdmpfalse
                                            high
                                            http://appsyndication.org/schemas/appsyn5rss/channel/as:applicationKDiddark.exe, 00000018.00000002.557734588.0000000005862000.00000002.00000001.01000000.00000028.sdmpfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            http://wixtoolset.org/releases/sMicrosoft.Tools.WindowsInstallerXml.Extensions.Xsd.vs.xsddark.exe, 00000018.00000002.559434031.0000000005ED2000.00000002.00000001.01000000.0000002A.sdmpfalse
                                              high
                                              http://www.fontbureau.com/designersdLMSetup.exe, 00000005.00000003.424621358.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.424738869.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.424486510.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                high
                                                http://www.fontbureau.compLMSetup.exe, 00000005.00000003.428643198.0000000005323000.00000004.00000800.00020000.00000000.sdmpfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                http://www.fontbureau.com/designersbLMSetup.exe, 00000005.00000003.431133719.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.431274097.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                  high
                                                  http://wixtoolset.org/dark.exefalse
                                                    high
                                                    http://wixtoolset.org/telemetry/vdark.exefalse
                                                      high
                                                      http://en.wikipqxgLMSetup.exe, 00000005.00000003.406860034.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.407217388.000000000A46F000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.407122395.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.407017293.000000000A46F000.00000004.00000800.00020000.00000000.sdmpfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      http://wixtoolset.org/documentation/error217/u32.24.drfalse
                                                        high
                                                        http://www.fontbureau.com/designers:LMSetup.exe, 00000005.00000003.429567950.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                          high
                                                          http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namedark.exe, 00000018.00000002.556628591.0000000003085000.00000004.00000800.00020000.00000000.sdmpfalse
                                                            high
                                                            http://www.fontbureau.com/designers/LMSetup.exe, 00000005.00000003.424339254.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.424486510.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                              high
                                                              http://www.fontbureau.com/designers/cabarga.htmlDLMSetup.exe, 00000005.00000003.429383019.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.428860600.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.429182478.000000000A46B000.00000004.00000800.00020000.00000000.sdmp, LMSetup.exe, 00000005.00000003.429027170.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                high
                                                                http://wixtoolset.org/releases/uMicrosoft.Tools.WindowsInstallerXml.Extensions.Xsd.sql.xsddark.exe, 00000018.00000002.557417725.0000000005742000.00000002.00000001.01000000.00000027.sdmpfalse
                                                                  high
                                                                  http://wixtoolset.org/releases/wMicrosoft.Tools.WindowsInstallerXml.Extensions.Xsd.http.xsddark.exe, 00000018.00000002.556791687.00000000053E2000.00000002.00000001.01000000.00000024.sdmp, WixHttpExtension.dll.5.drfalse
                                                                    high
                                                                    http://appsyndication.org/2006/appsynLMSetup.exefalse
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    http://www.fontbureau.com/designers2LMSetup.exe, 00000005.00000003.429383019.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                      high
                                                                      http://www.fontbureau.com/designersUKLMSetup.exe, 00000005.00000003.446234440.000000000A46B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                        high
                                                                        http://www.fontbureau.comalsFTLMSetup.exe, 00000005.00000003.429990990.0000000005323000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                        • Avira URL Cloud: safe
                                                                        unknown
                                                                        No contacted IP infos
                                                                        Joe Sandbox Version:34.0.0 Boulder Opal
                                                                        Analysis ID:562516
                                                                        Start date:28.01.2022
                                                                        Start time:23:40:43
                                                                        Joe Sandbox Product:CloudBasic
                                                                        Overall analysis duration:0h 11m 0s
                                                                        Hypervisor based Inspection enabled:false
                                                                        Report type:light
                                                                        Sample file name:LMSetup.exe
                                                                        Cookbook file name:default.jbs
                                                                        Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                        Number of analysed new started processes analysed:26
                                                                        Number of new started drivers analysed:0
                                                                        Number of existing processes analysed:0
                                                                        Number of existing drivers analysed:0
                                                                        Number of injected processes analysed:0
                                                                        Technologies:
                                                                        • HCA enabled
                                                                        • EGA enabled
                                                                        • HDC enabled
                                                                        • AMSI enabled
                                                                        Analysis Mode:default
                                                                        Analysis stop reason:Timeout
                                                                        Detection:CLEAN
                                                                        Classification:clean10.evad.winEXE@8/221@0/0
                                                                        EGA Information:
                                                                        • Successful, ratio: 33.3%
                                                                        HDC Information:
                                                                        • Successful, ratio: 93.9% (good quality ratio 86.3%)
                                                                        • Quality average: 71.5%
                                                                        • Quality standard deviation: 31.3%
                                                                        HCA Information:
                                                                        • Successful, ratio: 100%
                                                                        • Number of executed functions: 0
                                                                        • Number of non-executed functions: 0
                                                                        Cookbook Comments:
                                                                        • Adjust boot time
                                                                        • Enable AMSI
                                                                        • Found application associated with file extension: .exe
                                                                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, WMIADAP.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe, wuapihost.exe
                                                                        • Created / dropped Files have been reduced to 100
                                                                        • Excluded domains from analysis (whitelisted): ris.api.iris.microsoft.com, ctldl.windowsupdate.com, displaycatalog.mp.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, arc.msn.com
                                                                        • Execution Graph export aborted for target LMSetup.exe, PID 5264 because there are no executed function
                                                                        • Execution Graph export aborted for target dark.exe, PID 6416 because there are no executed function
                                                                        • Not all processes where analyzed, report is missing behavior information
                                                                        • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                                        • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                        • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                        • Report size getting too big, too many NtQueryValueKey calls found.
                                                                        • Report size getting too big, too many NtSetInformationFile calls found.
                                                                        • VT rate limit hit for: LMSetup.exe
                                                                        TimeTypeDescription
                                                                        23:42:54API Interceptor2x Sleep call for process: LMSetup.exe modified
                                                                        No context
                                                                        No context
                                                                        No context
                                                                        No context
                                                                        No context
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):46
                                                                        Entropy (8bit):4.34389537982896
                                                                        Encrypted:false
                                                                        SSDEEP:3:YTyLSMRWQYHJHKNm8HQ84:YWLSwWpZ
                                                                        MD5:61F20331CD484522E8503163361D7BBC
                                                                        SHA1:615B46AE0BF94F50862B61961AB756D3092600A7
                                                                        SHA-256:707624B59A3A8DFAB92BABB860322D75711F7F2742A412312B23ED13C9A3BD28
                                                                        SHA-512:E5E18816D751C134597162FBE2972D26FB8A10160F503243A8CB6B3D85B1DEB441BBA4CAD0C2F888835E82CB73F6A5FDC70DD94D7804211C4B61620751EEAEC3
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"version":"1.0.4835.18","cachestate":"final"}
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF, LF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):839657
                                                                        Entropy (8bit):5.442433940182848
                                                                        Encrypted:false
                                                                        SSDEEP:12288:1ZUlHLMtshpu8NFvBendUEox6QmXWZUyus9+:kLMtshpu8NFvBendUEox6QmXuus9+
                                                                        MD5:4FD2C7A5C559A047B953CDA0B21E6B6C
                                                                        SHA1:68C5D2CCE4EB1A28F438FEAF6F2F552D669B8D7F
                                                                        SHA-256:9355AF5DCB5B82EC0C536F98EADA13D1D544A2EEBBE5F065DB8567DEE8F08896
                                                                        SHA-512:6CDC204C225B07E972A038090C1B17D6805BC07A7E56DCB63C3D55F405658486721A4F7A037730A175768D12CAE5A7638236B2129DF75F39F62A3E11A8DD6946
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:.<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html lang="en-us" xmlns="http://www.w3.org/1999/xhtml">.. (funnelweb10) (C) 2019 Toshiba (Australia) Pty Ltd -->..<head>.. <meta http-equiv="X-UA-Compatible" content="IE=10" />.. <meta charset="utf-8" />.. <meta name="format-detection" content="telephone=no"/>.. <style data-copy="false">.. /*<![CDATA[*/.. .invisible{position:absolute;top:-9999px}.visible{visibility:visible;position:static}#fwFrameSDKContainer{height:6.6em;width:100%;display:none;padding:0;margin:0}#fwFrameSDK{width:100%;overflow-x:hidden;overflow-y:scroll}#dlgProgress #loadprogress{display:inline-block;margin-left:.5em;margin-top:.7em;background-color:transparent}#dlgProgress #progressMsg{margin-left:.5em}#restoreProgress{display:inline-block}.restoreHeader{text-align:center}#buttonBar{position:absolute;bottom:0;z-index:10;visibility:hidden}.restoreHeader h3{text-a
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:HTML document, ASCII text, with very long lines
                                                                        Category:dropped
                                                                        Size (bytes):119129
                                                                        Entropy (8bit):5.4956605818236985
                                                                        Encrypted:false
                                                                        SSDEEP:1536:M/SoxMzCGwvynXw3iUQDous+GUyvjyw6ri3GE:M/Su2Cvy21Qsus+GUyvj2YGE
                                                                        MD5:D3E441A701FDE8D1F75FB94EEE9D9A16
                                                                        SHA1:E87085A9F50EF1FCEF7643D883C135FD7EC2F4E2
                                                                        SHA-256:390D3481AE061BC3084047D6A69F1B8FBE6CD2E7A0825B86E847E904B211A075
                                                                        SHA-512:157906C1D0BA439AE516F13AC3A8B51612E503943E78602E4DA22DC6019BB11F4B77DBD4CDD9446B165AABBC475E529C1DFB60279B45B552756045CDCC3634C8
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang="en-us" fwcachemode="static">. . * fwAppMenu.html. *. * (funnelweb5) (C) 2018 Toshiba (Australia) Pty Ltd. *.-->.<head><script type="text/javascript">.//<![CDATA[.//*** FWAPP AUTO ***..var FWSDK = parent.getFWSDK('sdk', 'defaultmenu');.var TAPJS = parent.TAPJS.getRef(this);.var FWLOGGER = parent.FWLOGGER;.window.pluginTarget = 'menu';.window.onload = function(e) { FWSDK.onTabLoad(this,'defaultmenu');}; .// .</script>. <meta charset="utf-8" />. <title>Main Menu</title>. <script type="text/javascript">. /*<![CDATA[*/. /*. * fwAppMenu.js. *. * (funnelweb5) (C) 2019 Toshiba (Australia) Pty Ltd. *. */.var userSettings=function(){var e=null;var t=null;var a=null;var n=null;var r=true;var i=null;var l=null;var u=null;var s=null;var d=[];var o=[];var b=[];var f=[];var g=[];var c=[];var v=null;var p=null;var h="_tapjs_ps_active";var S="_
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:HTML document, ASCII text, with very long lines
                                                                        Category:dropped
                                                                        Size (bytes):100287
                                                                        Entropy (8bit):5.4709075315223705
                                                                        Encrypted:false
                                                                        SSDEEP:1536:2hS4CGwvynXw3iUQDous+GUyvjyw6ri32TfKE:2hS4Cvy21Qsus+GUyvj2Y2TH
                                                                        MD5:B339424140EAB43F92872A256F0C41C0
                                                                        SHA1:5CB776FD6BC97288819B3C2F325DBED3F6AB02B0
                                                                        SHA-256:ED727AC62B4D98739EA5DDF9A1DA2D73086C66E36BEF9F922892DBE6DA5681E5
                                                                        SHA-512:C3A634A4D1A0D4402F157CADB663B3869951BE97B5F11A94D2A3472E1FF676D53AC11264CAE336EBB9ADA6769064BAF7A8401AFF4CFA0966CAAE179BDC852DDC
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang="en-us" fwcachemode="static">.<head><script type="text/javascript">.//<![CDATA[.//*** FWAPP AUTO ***..var FWSDK = parent.getFWSDK('installer', 'welcome');.var TAPJS = parent.TAPJS.getRef(this);.var FWLOGGER = parent.FWLOGGER;.window.pluginTarget = 'main';.window.onload = function(e) { FWSDK.onTabLoad(this,'welcome');}; .// .</script>. <meta charset="utf-8" />. <title>Welcome</title>.. <script type="text/javascript">. /*<![CDATA[*/. var welcomeMode=null;var btnPanel=null;var checkSelects=true;function fwPluginShow(e){FWSDK.jCall("SYSTEM.getLocale",[false],function(e){var n=document.getElementById("langSelect");for(var t=0,l=n.options.length;t<l;t++){if(n.options[t].value===e){n.selectedIndex=t;break}if(t==l-1){n.value="en-us"}}});FWSDK.waitFor("InstUtilLoaded",function(){var e=$("#buttonsTemplate").getHTML();btnPanel=FWSDK.GUI.updat
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):2255690
                                                                        Entropy (8bit):6.181031401626715
                                                                        Encrypted:false
                                                                        SSDEEP:49152:l6QmXuuGWLMtshpu8NFvBenAUEX8bw601:OB
                                                                        MD5:49C42825DB3125839E1AF0BB487A70BA
                                                                        SHA1:5F9817D6E114E7488AF011FA63726CC8B10C231B
                                                                        SHA-256:9BDC989140DC1D4F27B012B70BE8FE4CED32590DF1C960709DFAA04B26FB42A0
                                                                        SHA-512:38C1E4F9A0F9A02A6668CC1CBA915CF3B153B35A2EF7E3DC1B1C8B459AF324389BEF8F5E0D972980C4F5C6798ED9C8D3F3C31BC70F9D21E43251545C61F9F273
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:6.......memcache://sdk/themes/default/default/images/drive.png.PNG........IHDR.............V.W....gAMA......a.....pHYs..........(J.....tEXtSoftware.paint.net 4.0.19..d....IDAT8O.OK.Q.G.t..).......]..+7:&.....:1.L....5.1cb..B..4.B.#M...%....P.v......=\.}.............Y.z.....[4.?~.ONN..p~~. .Z..k. .v....Y.|L.....dK...d..JU.|.D:.'..Q(T.f.T..hj....[.E.".{...'......+_.KdP?.Y.(...[xf.DQ.-....^...[...:C....&#>..F......D.)/.a..G..i.0.....W..&1.{.9.C..m.T-....[..Y......7-.........U...Iu.`(.....juW2e3/-3.;x.?h..S7.s|\s6..5>n..(...hOr-y...r...J..}.Y.;...X.@/.......IEND.B`.........memcache://sdk/fwAppIndex.jsvar JSStartTime=Date.now();var FWResolverCache=function(){var e={FETCH:1<<0,DONE:1<<1,ERROR:1<<2};var t=0;var n=null;var a=true;var i={};function r(e,t){if(e){var n=atob(e);i=JSON.parse(n)}if(t)t()}function l(a,r,l,o){var u=i[a+"|"+r];if(u){u.state=o?e.DONE:e.ERROR;u.data=l;var s=u.cb;u.cb=[];s.forEach(function(t,n,a){if(u.state==e.DONE){if(t.cbThen)t.cbThen(u.
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):45
                                                                        Entropy (8bit):4.133643863468258
                                                                        Encrypted:false
                                                                        SSDEEP:3:YM5dVCVLQcK+mjHY:YM5XCtQf+mj4
                                                                        MD5:EE3916A8ACDB88541DA47B7DECD0E79B
                                                                        SHA1:03D3C42ACFC78E2BF33BA397848EB80D06C6685B
                                                                        SHA-256:DF22F2A8DA0BC59118DDEC1956A886F4760DC3A714A1BE05C65F2BC2EB20D46B
                                                                        SHA-512:3DBC0E5BEA4D717FCCF0CAA1629EFF2B517693A022F8777310836297FDDE8348D46731683A75FAF8E01159CE230D1127F03A114442FA84691E77DE8D0CC8CF15
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"id":"9511D742-CA40-42CE-A2BE-0175921F1BCF"}
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:Zip archive data, at least v2.0 to extract
                                                                        Category:dropped
                                                                        Size (bytes):11355
                                                                        Entropy (8bit):7.964212022711314
                                                                        Encrypted:false
                                                                        SSDEEP:192:+N7d8Lnq4DXAndaVZkBStSAWsDVOHLzfiHPR3wwioXwC0UZppungklnX3Ad/ePEm:a6LnF4daVZkBStvWnHLzfMPNnNwCXZpq
                                                                        MD5:AD3DD5A67FF065E753E046E25035EFE8
                                                                        SHA1:EAC7E6E01D117F872C2110957177684849EC0D61
                                                                        SHA-256:50D71FAB9047265808DCEBA4573AA0785F01AF34FEBF8D9004DF20B0E8E37AC6
                                                                        SHA-512:3B2490A48B2FF1AC76CEDBDFA5B7D1503EDFCDBB9282541D6A795345D56F2C72F635A83E15AEAD743BD5CE71981E7EEBB82A9502554E35DCB633008A6DA2C91B
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:PK..........rO~(.-J....}..4...printerinstaller/resources/dlgAdvancedDiscovery.html..ks.6.{g...%WQ.M..(q:...tud......<..Y.iRCB~4......A.....9..$.X........~..z...g\......;..S...oY.e..ml...-..[.yg.%.:...H.=....1.C...[......y.L...o..L..&./...[.E..:.w.M\."w+|.....je.....&../....P..m.........jB.9..6.....x....Ns.s<....,t.......L.."..........$.cw].}.....2..%6/.....P..W.P..J7. h.8.n.=.hO..rf.-<..4...=...q......u.D...^@..^@o{....@O=b.M{.&.g.|..3....c.....5q..."..>..........`r~88..{'........m.$.v;.w....!....^....0.>....D..U.V.....4.T.V`Ae.sc.d.E/;..)...P..9...]^.......].9.i....]..7...2.rBS....|m.$M..;...v..C.JX....a:.d.W..L.%.D#..Z..X.F. i%.6.k.t:.....H7.C..n.u+.p8..2...E.~.?.....a.z>.M...I/t..V.{....6..+4..)...t."o.2f.!.U.6J.FD(#..x..C7.I......i..Ht1b.......W...wo8..N'..c..b.=....E..l.Z....o,..<T@j.+.:.....:.....Q...%(..q.#............0&...1;Nv.....p.{{8<..|.+0."..K....x.&.2%.O......I.ud...0/9,$.G...9x....2....D...t.[..ELO3>.}&.||..D.2~.|$..
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines
                                                                        Category:dropped
                                                                        Size (bytes):633
                                                                        Entropy (8bit):5.030968447010093
                                                                        Encrypted:false
                                                                        SSDEEP:12:YE6GDXBgdH9RWYqEjuHK+187agBfXuLkmgHXCD6wREWGFq81ZXB2dXLhK3fKrW:YjGLBglGYZjIR14pBfXyOwBIT1pB2tLe
                                                                        MD5:29CF7C2CDA4181560A89150F6752DD2A
                                                                        SHA1:A068BE323C9869E14F2340B0A55D776D9643AC45
                                                                        SHA-256:E0F0C95E79A7A1DFEFFF4701287CB9901704FCC23F23BC161C687A3B2FDAD230
                                                                        SHA-512:AF2841F3C66FB32B1C4CB1413DAD2C357B8954370AD12411F9580505F6A12E0F334A6A981BBBC8BAD1F5BA999C27DE63A56F51F12F08DB9535942734A75AF265
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"Files": ["metadata.json", "printerinstaller/resources/dlgAdvancedDiscovery.html", "dsdk/resources/snmpOid.js", "dsdk/resources/advancedDiscoveryModels.js"], "Namespace": "Lenovo.UNI", "Version": "1.0.4835.18", "MD5": "ad3dd5a67ff065e753e046e25035efe8", "Type": "RAFPlugin", "Archive": "Lenovo.UNI.zip", "Metadata": {"HasExternalLicense": true, "PackageAttrib": {"GlobalResource": {"Resource": ["dsdk/resouces/snmpOid.js", "dsdk/resouces/advancedDiscoveryModels.js", "printerinstaller/resouces/dlgAdvancedDiscovery.html"]}}, "License": "License/locale/license.txt", "HasExternalReadme": true, "Readme": "Readme/locale/readme.txt"}}.
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:Zip archive data, at least v2.0 to extract
                                                                        Category:dropped
                                                                        Size (bytes):641675
                                                                        Entropy (8bit):7.997226004340185
                                                                        Encrypted:true
                                                                        SSDEEP:12288:ycyQH7KV85OnnqnaAkPzrRb857nJvRig95g41BHskKWKEYWpmuIK5dOu:ycvb7wqna5z+7VhBHsNWpmtKjOu
                                                                        MD5:08B7A18E665C4BA85B5DCDF4F2963877
                                                                        SHA1:3AC1C001B7A75DCB1AB7F39E61CC730F2E7E3212
                                                                        SHA-256:C8F3743B38D399020822218B1723D5C2634AD14BECD5CCD45CFC21BC2E78B1AE
                                                                        SHA-512:0A7B14A25F7A010B559E8E7BBB287E7523A40DBACC261BE307EBF5E1185D4E5E4F6507AC829E5291C4E445C220D5A30E95E7F0AE5BE9E4DB20FD73D19D2C48DC
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:PK.........[4P..W*.T..........strings/pl/strings.txt...n.X.7.......vw.L.... ..D.JS"[..t...Zb:i.>]R%..0S..<..U_c........@W.E....6.\.8...]N.._..\#.D.....:.8...p.'..u.\..f.R9-.J..7...h6...(..>G.z.I...:C.=-......o...a.K....M..Z.w;.^\.#...f+Y.....j...J.....x..?Gs.*\....e8...d<.\<......m...v...'^8....J...|.......B...._~k...s|..A4...E.d}..f3c..+c....hr.Y....=.n...?a...B#1..+.1.9n.r....y...1K......;.T."..=.......v..q]3.e<_GK.).J..fT...m...z..e.Ef.gV..M.fW..Y.C%....A0.......V;@m9...j......Q.Z..[.#..@..\h.,.7.c.....o\...}4...A!.Z).j...-.(d...?..u^..."..</.gUM..I..`7~[...3k.U.B......XM....u..R.5.Y,.Y7..l.Jn.5%....#.Q.....3.B...n...m.o...t]..,.9m.i.S/L..p..).....'.4.r..!O....$|.....ql..a.V);...........d..M...`...<..i2..DP.....F.0.4..[.w.h6G...,=....xZ`Z..2.......O.........2....D...\...t...w_...yT...6.|.q.m..f.L....?.I...{...K..y.i..&.y<......{(_.{P./...zW.q...n...=?I..y....x>I.+.......ukZ...~...P.d.k....t..6?.!4p...mp.{.p.......5..x.........P.?1..f.92.
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines
                                                                        Category:dropped
                                                                        Size (bytes):2722
                                                                        Entropy (8bit):4.905174343607544
                                                                        Encrypted:false
                                                                        SSDEEP:48:YIoNkhIv26hQwYUPfmQBFkVhE23nyoKToEsSCLlP5ALQpZ8iKqpmgn/tUn6ykhkH:lskhIv26hQwYU3mQBFkVhEGnyRzrylPs
                                                                        MD5:BEF29C406A269C90C94F14900D0D932E
                                                                        SHA1:81AE394DCE681B6671CE2F8B4C16C697DF8D1CD3
                                                                        SHA-256:9C689D64628559FA112080BFDA7BDDAA956EF0C65F73555670D1F4488E5D34DC
                                                                        SHA-512:A4F71E5D56D1F5D3DF4AA4167DE721943C1B1A90DF9B050887C5C21A132862592AE540D9B96B48B93891D97B985AC403B4A4DB713E39D3D4A8442521B5469311
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"Files": ["resources/SM2PTFeatures.js", "strings/da/strings.txt", "resources/advancedDiscovery.js", "resources/preview.js", "resources/license.js", "strings/fi/strings.txt", "strings/zh-tw/strings.txt", "strings/it-it/strings.txt", "help/en-us/tabListFooter.html", "help/de-de/tabListFooter.html", "strings/nl-nl/strings.txt", "resources/paper.js", "resources/userDataDlg.inc", "resources/propertybag.js", "strings/tr-tr/strings.txt", "help/ja/tabListFooter.html", "main.db", "strings/zh-cn/strings.txt", "strings/pl/strings.txt", "strings/pt-pt/strings.txt", "help/es-es/tabListFooter.html", "resources/printspooler.js", "strings/pt-br/strings.txt", "resources/printTicket.js", "resources/previewWM.js", "resources/controlPanelCheck.js", "resources/customizeDlgs.js", "strings/sv-se/strings.txt", "strings/cs/strings.txt", "strings/de-de/strings.txt", "resources/customizeExtensions.js", "strings/es-es/strings.txt", "sm2dtd.json", "resources/localdiscovery.js", "resources/paperLabel.js", "resourc
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:Zip archive data, at least v2.0 to extract
                                                                        Category:dropped
                                                                        Size (bytes):175026
                                                                        Entropy (8bit):7.970168884358179
                                                                        Encrypted:false
                                                                        SSDEEP:3072:+uqf4D7hD4C/g3/9FovAAJE+4Evt4RccuaGO1yhQEfClM6MILjHDTF5esV9K9dQ:U4p4C+eJUuaLyCkxqLjHV509m
                                                                        MD5:AC76463029240D920806DBC02879EB89
                                                                        SHA1:B4FB47B5D297955CF6D0E36C7EEFFAF19FDE0FFE
                                                                        SHA-256:0B5D2A464FCD848D2F2E1FA1C0DE8B852B88BE9667BD96B51DBFBC075A8FA4AA
                                                                        SHA-512:DF0940E5E747EE30B41EEAC0F4E45817D8D1E799390A95B0D1F7A95E992A5F4AF13AD2A46E73096F5949387CF10DC5AF7EF29919B2C6018945CD49B1BD15A716
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:PK.........[4P...U....M......strings/es-es/strings.txt.<]o.H..... .... Qd.J.7 ..I.P$...dq........7....<..<,.m.a.....pU.Av..Nfs.w..A$uWUWWWWWUW....n.!...R.y..L..>.....t:.....&..C..my.$.z..{R....L_MN_|..kx......_8V....k.....j.........}....-u.'.4#.d2.A,....s.5.K...BK...[vd.N.;..s.....TD.&..,....W...0.}7v..).ZV'w.z.%0..c^...p.i.......n..u:.F6UMv..+...Y..z..>..:-.:..........@7..-g.4<.X5I.+J...Y............Ln."Gn.XS..d..!.iVVdG6........V.....'..-..{.'\.f..KAc..(....[182..hU.Q}l...*..u.....l.kw.'.+..[r.%%4..V...M.dU...m.r.3...0Vn.....!..s.&..,.S*..a.{P.2/`..>...6....sK...L.. ..v....g.W~.Z.V.y.V.]^j.z._0..T0.8v..H...t.hQR....q8h$.j ...-...N..............%..$.4....~..pX...".Yz..b..Jg.......... ..|w.e.dI.s/."[h.5..i..................}............[*..F}"._h.....Pg....0..K..Z^..l.`$Y..B.J.&..SP..[W`..=7.~...5h..0h..v........=..RK]...n2P...a.4.|... ...q........Z.s........fM.[;..O...w...m.....s.-l..6...6.....O............k.b.u......*6....l.?.
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines
                                                                        Category:dropped
                                                                        Size (bytes):3768
                                                                        Entropy (8bit):5.11665521595365
                                                                        Encrypted:false
                                                                        SSDEEP:96:Eg16Po95hfM9Kd4iGziCjbP9j0d1jcLC6e5MGn5fR5M3PMi6cxzmBfO:JT95hf0Kd4iGdm5MGndReMi6c4fO
                                                                        MD5:67689F6A40C69B40F2422712DD8B8979
                                                                        SHA1:C960576745A0D51C255971BC2FDB6A66883FCFE5
                                                                        SHA-256:5A1174A81454F4F200702E97D486C504D5F07742DECD9EC61BF5EAB5A1D7129C
                                                                        SHA-512:DDABA9A57257CD981C7BBB49C7250AB78A421D18133CB47783DE01B11BC1FC68A873398006B236E7B56D361D2BAC396BDB02960B774A48353AB2E459CEAA92B1
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:{"Files": ["themes/default/default/images/Printer_Add.png", "Finish.css", "Install.html", "strings/fi/strings.txt", "Repair.css", "strings/da/strings.txt", "resources/InstallerUtilCtrl.js", "themes/high_contrast_white/default/images/check.png", "themes/high_contrast_black/default/images/check.png", "Change.js", "resources/InstallerUtil.js", "ReadyToRemove.js", "themes/default/default/images/check.png", "strings/zh-tw/strings.txt", "strings/it-it/strings.txt", "ReadyToRemove.css", "basethemes/win7/ui.css", "Upgrade.js", "ReadyToRemove.html", "strings/pl/strings.txt", "License.css", "strings/nl-nl/strings.txt", "themes/high_contrast_white/default/images/Printer_Add_Hover.png", "strings/ru/strings.txt", "themes/high_contrast_white/default/images/Printer_Add.png", "Welcome.pt.js", "ReadyToInstall.js", "strings/tr-tr/strings.txt", "license/en-us/license.txt", "Welcome.css", "strings/zh-cn/strings.txt", "strings/en-gb/strings.txt", "strings/pt-pt/strings.txt", "Repair.html", "resources/dlgDo
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines
                                                                        Category:dropped
                                                                        Size (bytes):891
                                                                        Entropy (8bit):5.0889374039090285
                                                                        Encrypted:false
                                                                        SSDEEP:24:YacTpM3H9c9vt3j0m9Nl9b909z2rx136l5ZajvKPOv/6nx4bQEGQ:YacTpM3dcdj0KNfB0zaD65Za7KPcy4/
                                                                        MD5:16550DED7709594EB7D4E98180B3BB82
                                                                        SHA1:66997E1D7C82424E7BC04E13F7C3004CBAB58405
                                                                        SHA-256:65AFF216AC92F661E294519E35E9293B81079DA6AAF85C04F25FB68FDAC51249
                                                                        SHA-512:6BC14FE147AB0268FEBFA6C62A3A93FD46ADDBB26728249DB96EE47C4202A105A2C5F024FC00F15588D7164FF4FA04786A863666D1B972A12B2C3781CB980C15
                                                                        Malicious:false
                                                                        Preview:{"Files": ["resources/AutoConfig.js", "Settings.pt.js", "printerinstaller.db", "metadata.json", "resources/dlgInvalidPort.html", "resources/dlgDoneTestPrint.html", "resources/dlgFilePicker.html", "Settings.js", "resources/InstallerUtil.js", "resources/dlgSnmpSettings.html", "resources/dlgAdvancedDiscovery.html", "Settings.css", "Settings.html", "resources/dlgDuplicatePrinter.html", "resources/dlgEmptyPrinterOrPort.html"], "Namespace": "printerinstaller", "Version": "10.62.219.7", "MD5": "fd485e7b017c41b0073081bf25121395", "Type": "RAFPlugin", "Archive": "printerinstaller.zip", "Metadata": {"Rules": ["printerinstaller.db"], "PackageAttrib": {"GlobalResource": {"Code": ["resources/AutoConfig.js"], "Resource": ["resources/InstallerUtil.js"]}}, "Tabs": [{"PT2SM": "Settings.pt.js", "HTML": "Settings.html", "Displayname": "%{IDS_TAB_SETTINGS}", "Id": "Settings", "TabOrder": "300"}]}}.
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:Zip archive data, at least v2.0 to extract
                                                                        Category:dropped
                                                                        Size (bytes):42200
                                                                        Entropy (8bit):7.973462415126172
                                                                        Encrypted:false
                                                                        SSDEEP:768:IhGi9KwESOBRLyg100e2oMExgsUF44WInEzsg/UlSqVCvpN30Bg:/ivENGTnM+NUFqfmlrVQH3Kg
                                                                        MD5:FD485E7B017C41B0073081BF25121395
                                                                        SHA1:BD76AD164F6C393597C8DC5EC63E23129783F1D4
                                                                        SHA-256:C672F122667CAB3EB7BB3121158C08C7979AAE2AA79FB35A80665833F0B00121
                                                                        SHA-512:57FD0EB86F7FB7758A4BA7C006AC1018B8096A7EB4A1F75F052AD495C0D2130F88410F37B0E02D4CB3197EE513D405B23145F91714C6DF5AD7E9EB328E7EE41B
                                                                        Malicious:false
                                                                        Preview:PK.........\4P.c+k............printerinstaller.db..xT...]..g.4..%.l.........A...A*.s.=.....=.I..f7....V.((.EEE..HcQ........~.........;3.d.........}..o...oN....:.-..JQ..=....t.8..a......L.[...1.......V.5}. ..g..R.}.....l.+c1...........6.......l...|...n...y4.N+.//....L...d...+.^.J...9.d..JA.|N!.e...]......,T.C..yOP...A.xS.5#C..A.;E..M..xb;Y.c.nW.]....R.13.owJ..K...q6.$..o..t.,...]-H.......i:/..o."rU../Jn.FS../!.....R...,c...c'.T!v.o..nA..q...N<(...V.U.........q@D]-..._.j.T.S.........2.1..l.d..,/4(=..~./....g'....:.$..J.{..&9.s...?".E?.2..s....=..}..xkz.6..R..s....#...T3..x../t....t.bXG.{..'......kRlX{.t6..J....0].}..:0......,..,..Y9.S.~.&.W!......@...n.k...........A]Q.>m........t....J..!.x.)x.6A........./J...[&..R....J..=k.$..Bq. u.)...Mv..@.b.H...Z..x..*...;...{0 H.Ay....N.A.U.L.]A.<.<.l,...%..w..t.S(z.NC.[.......(.s........M...t.f........}k?9..K;:.#...`.n6h.<0....^......,.g..n.N.<.............-.9.n.......(..............E.(......W.....
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines
                                                                        Category:dropped
                                                                        Size (bytes):9606
                                                                        Entropy (8bit):4.942967041629648
                                                                        Encrypted:false
                                                                        SSDEEP:192:Q3kX4r8HtfkGTv/GMVAUL5jFmedtThplE43w25VpLy2hi9tN:Q3kX4r8Htf5TnJVAUL5jFmedttplE43m
                                                                        MD5:F2C453BA6CBF9011580D3AEB23188090
                                                                        SHA1:59E97F572F0AF63438CCA30AE94FDCE8019D5146
                                                                        SHA-256:760BC0B42FE5B30F1C3279358C45E0D7F2B32C094ED415497746D3B5D2042FF0
                                                                        SHA-512:F179783B744C1E1447C6B13EF435B67183AF95491CDA874EDD4BCCA008876994B67F18A5CFFD85612F4F020B60ED6B4DF40D09A4D150CB478853171CF4BF6545
                                                                        Malicious:false
                                                                        Preview:{"Files": ["themes/default/default/images/page32.png", "themes/high_contrast_black/default/images/Cal_Month_Previous.png", "themes/default/default/images/Spin_Plus_Disabled.png", "fwAppMenu.css", "themes/default/default/images/Spin_Minus_Dialog.png", "themes/high_contrast_white/default/images/Spin_Plus_Dialog.png", "themes/high_contrast_white/default/images/Tab_Cursor.png", "themes/high_contrast_black/default/images/joinbottom.png", "themes/default/default/images/trash.png", "themes/high_contrast_black/default/images/minusbottom.png", "themes/high_contrast_white/default/images/Spin_Minus.png", "themes/default/default/images/Password_Peek.png", "themes/high_contrast_black/default/images/plus.png", "themes/high_contrast_white/default/images/Dropdown_Close.png", "basethemes/win8/ui.min.css", "basethemes/win8/theme_default.subs", "themes/default/default/images/minusbottom.png", "themes/high_contrast_black/default/images/Spin_Minus.png", "themes/high_contrast_white/default/images/Dropdown_O
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:Zip archive data, at least v2.0 to extract
                                                                        Category:dropped
                                                                        Size (bytes):316936
                                                                        Entropy (8bit):7.9563112579516835
                                                                        Encrypted:false
                                                                        SSDEEP:6144:W7DYU6EbHdE/EWp5/BOhxrKZ6SNEq03dKYQe4Crq4c2ZnurlQCHSdvQcw:WfN6EbHdmh6SDgdKQh1xrCHSdvq
                                                                        MD5:1F04FD81F9CF6CB5CDB242DD5B0F8228
                                                                        SHA1:06B4D5F75BF4A8CDDC6F67090820D51B146172B3
                                                                        SHA-256:A11FA55CC150F43BF891C09A335F45451E68470638B42F2B6AE75248C509A877
                                                                        SHA-512:AF3E434396E4CDF6ED25C64A554ED2104A80CED977FB94D7BC40A12FBB459778778BBACBB7F3B5CDB61A889734880DE8DFF2F81C0BF4C16798493573B93E2E0C
                                                                        Malicious:false
                                                                        Preview:PK.........[4P?.@.........9...themes/high_contrast_white/default/images/Tab_Arrow_L.png...s...b``...p.... ...$.....R..N.!......?.ry.|B\......?z.|..KI._0C....M>..........|% .....PP..5..(5.$3?O!$37...P....n.,..T!.R...VR.X..........Y.Z._.]...l.b...:.O........|....t.7$\W..c.....Zw....37...O..._~J.......)...PK.........[4P...#........B...themes/high_contrast_black/default/images/Dropdown_Open_Dialog.png...s...b``...p.... ...$.C..).b'...........B.>!..1...%L@Y.. .`.....M.....,..,f`.+.a.l....b%..%.E..%..y.!........&@t.d.W...........T....T........b..`..{6...9{.8.hLLN..;..b..........@hY...u.6...*.........u.ihl.4..p5.r..t...]....-.YV0.h......:..&.PK.........[4PZ..:........?...themes/high_contrast_black/default/images/Spin_Minus_Dialog.png...s...b``...p.... ...$=........<C888n?.............9@... .`.......y.......|% .....PP..5..(5.$3?O!$37...P....n.,..T!.R...VR.X..........Y.Z._.]...l.b...:!O.........6.ow..:T..y.'..1......)...PK.........[4P...r...........fwAppIndex.html.X.O
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):250
                                                                        Entropy (8bit):4.470219065430858
                                                                        Encrypted:false
                                                                        SSDEEP:6:YsXgXBnXBpSCsU095dtigXBpnoC95dtigXBpNqOXiO95dtigXBpuLgNqOXiO95dz:YFXFXjSvU03igXjnoC3igXjkOXl3igXL
                                                                        MD5:0675FD9E1D8FE707E82313E1EBC16B78
                                                                        SHA1:281C399A1658C6147204AA40E5986734DDA4D8C4
                                                                        SHA-256:A028A00F96AF5EFBCCC48B2A05844A8941AB28F0D6FA724FE2081EB176808AE6
                                                                        SHA-512:7B0FACEA3857197EAE5E36C56F0913A0996C66A0A1EB660D9FD238B52089CB491636E5049D1CD4FABFDB274027CFC217104BC36724FB09DB8CC94B5FD8FBEE22
                                                                        Malicious:false
                                                                        Preview:{"InstallerPackages":["InstallerPackages\/Lenovo.UNI\/manifest.json","InstallerPackages\/dsdk\/manifest.json","InstallerPackages\/installer\/manifest.json","InstallerPackages\/printerinstaller\/manifest.json","InstallerPackages\/sdk\/manifest.json"]}
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):21557
                                                                        Entropy (8bit):5.042662537777511
                                                                        Encrypted:false
                                                                        SSDEEP:384:dyVFruYb4u5eC9FTlCQY9mWMC9FwUHj0ND:dm4C9GqC9FwUYl
                                                                        MD5:C8F7CA8B787802700A23FAC6BF16EF86
                                                                        SHA1:1DAF3E84F626ED7F387FDE65A5E1501C7F3FC1D6
                                                                        SHA-256:251B1561762E812A92CE0E089DE43162DF8591D20DF9E375E918927F4633CB6E
                                                                        SHA-512:D3764AF8EA3F38022658EB6589D8C92CC3E6B39425D7B48EA91E9FFC0D0CBF75979EE62A2432101824B940E69F55D89A9A76FB22E89DBFF418B33AFC612336D9
                                                                        Malicious:false
                                                                        Preview:{"state":[{"Metadata":{"HasExternalLicense":true,"Readme":"Readme\/locale\/readme.txt","PackageAttrib":{"GlobalResource":{"Resource":["dsdk\/resouces\/snmpOid.js","dsdk\/resouces\/advancedDiscoveryModels.js","printerinstaller\/resouces\/dlgAdvancedDiscovery.html"]}},"License":"License\/locale\/license.txt","HasExternalReadme":true},"target":"InstallerPackages","enabled":true,"deploy":true,"path":"InstallerPackages\/Lenovo.UNI\/manifest.json","ArchiveRoot":"fwdata:\/\/plugin\/InstallerPackages\/Lenovo.UNI\/","root":"fwdata:\/\/plugin\/","valid":true,"status":"new","Namespace":"Lenovo.UNI","Id":"Lenovo.UNI","Files":["metadata.json","printerinstaller\/resources\/dlgAdvancedDiscovery.html","dsdk\/resources\/snmpOid.js","dsdk\/resources\/advancedDiscoveryModels.js"],"Version":"1.0.4835.18","MD5":"ad3dd5a67ff065e753e046e25035efe8","Archive":"Lenovo.UNI.zip","Type":"RAFPlugin","Types":"Installer","GlobalResourceFiles":["dsdk\/resouces\/snmpOid.js","dsdk\/resouces\/advancedDiscoveryModels.js",
                                                                        Process:C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe
                                                                        File Type:Microsoft Cabinet archive data, 7941732 bytes, 111 files
                                                                        Category:dropped
                                                                        Size (bytes):7941732
                                                                        Entropy (8bit):7.998498399657889
                                                                        Encrypted:true
                                                                        SSDEEP:196608:bq89B9XAl43iVlYkceddiXLw+Kjh7u/2yN51jC4xVblq0tNcVSZ4:br7MBAKjBu/d1m4TtFy
                                                                        MD5:43C42D19035D99EB5DDEFB7C15604D40
                                                                        SHA1:227D55DA8D2D7DBA40071690D5F8F5EFEB87DF02
                                                                        SHA-256:9C846B5338230ECA5EB1181A232CB0D7BA70B3953DDF747A35F13DD1068E60EE
                                                                        SHA-512:5B54762E44A6950879C7CC08DADADF729D029B20827260E8B242610ACF5D6676B87649DA3CF243EDA14E77539F7A6C17FA840BE87F9A3956619DB34F49EF3121
                                                                        Malicious:false
                                                                        Preview:MSCF....d.y.....d...........o...........J....Xw......nw.....[.w..... .w.......w.....c.w.....|.w................P.. .0...........4P.\ .u0.7....z.....P!l .u1..p...}....rK.p .u2.:.........rK.k .u3.dn.........P+l .u4..@..o_+...4P.\ .u5.....o.-...4P.\ .u6.....oK;...4P.\ .u7..!..o.>....P.. .u8..$..H?@...4P.\ .u9.....HcA...4P.\ .u10.."..H[B...4P.\ .u11.....H}E...4P.\ .u12.....H_K...4P.\ .u13..z..H.O...4P.\ .u14..~..HwQ...4P.\ .u15..2..H.T...4P.\ .u16.....H'`...4P.\ .u17.....H.i...4P.\ .u18.....H.w...4P.\ .u19.....HYz...4P.\ .u20.....H){...4P.\ .u21..'..H.}...4P.[ .u22..)...%....4P.[ .u23.&....N.....P+l .u24......O.....P+l .u25.>....P.....P+l .u26......Q.....P,l .u27......Q....4P.\ .u28......i....rO.. .u29......i....4P.[ .u30......@....rK.p .u31...........rK.p .u32..........rK!p .u33..p........rK!p .u34..@........rK#p .u35......X....rK$p .u36......(....rK,p .u37..........rK.p .u38...........rK.p .u39......X....rK4p .u40...........rK5p .u41...9.......rK8p .u42...........rK,p .u43..`........rK
                                                                        Process:C:\Users\user\Desktop\LMSetup.exe
                                                                        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):8550648
                                                                        Entropy (8bit):7.968086138202255
                                                                        Encrypted:false
                                                                        SSDEEP:196608:KfUVq89B9XAl43iVlYkceddiXLw+Kjh7u/2yN51jC4xVblq0tNcVSZT:6Or7MBAKjBu/d1m4TtFp
                                                                        MD5:ED2B2F8988D6123D440982052A65D364
                                                                        SHA1:78C33B6C5E06055208D212EB582D217DA128C5B3
                                                                        SHA-256:C19F9CB4159FC8BFB27F1935BEED5A5695BD45EF1BB32B7F14747C007D77EBFE
                                                                        SHA-512:1DBF4BAFED1896A5389C37178845ABE22229A45AE60C2CCF0A8B8327F128E29280378F56D6C63ED8BFCB42EA05E80997BBBCA255F39D99C14835F522ED64B849
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A!.S.@...@...@......@.....y@......@..."|..@..."{..@..."z.#@...8...@...8...@...@~.PA...#z.N@...#...@...@...@...#}..@..Rich.@..................PE..L......Z..........................................@..........................p......"S....@..............................................V..........h\.......0...=..Pv..T....................v......0p..@...................4........................text...7........................... ..`.rdata..`...........................@..@.data...0...........................@....wixburn8...........................@..@.rsrc....V.......X..................@..@.reloc...=...0...>..................@..B................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:XML 1.0 document, Little-endian UTF-16 Unicode text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):50246
                                                                        Entropy (8bit):3.6955218104814
                                                                        Encrypted:false
                                                                        SSDEEP:384:XZBX7/wI+oEggZZxwBzk1XchS0c7ZPlhDArZlER:XPLd+oEgsZxw1aXchSthUtlER
                                                                        MD5:368A0EBDA7952E7578809F7F0BFA1378
                                                                        SHA1:47AB7E43A5A4DE1829435681FDF7AEED2E73CAFD
                                                                        SHA-256:58F5126E6FFBA0DD48CE907B88487B98C005D13D51A1FB81098FE6EB80D215CB
                                                                        SHA-512:31328DFC2B1B6D1A66720B16579AD6C7DCA6FEB885D2920A0CD66C3EBE7C4755CC93CCEC0634568A088B86949781C363A2AC36ABA94CA5DBBF861D976C069E65
                                                                        Malicious:false
                                                                        Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.B.o.o.t.s.t.r.a.p.p.e.r.A.p.p.l.i.c.a.t.i.o.n.D.a.t.a. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.w.i.x./.2.0.1.0./.B.o.o.t.s.t.r.a.p.p.e.r.A.p.p.l.i.c.a.t.i.o.n.D.a.t.a.".>..... . .<.W.i.x.B.u.n.d.l.e.P.r.o.p.e.r.t.i.e.s. .D.i.s.p.l.a.y.N.a.m.e.=.".L.e.n.o.v.o. .U.n.i.v.e.r.s.a.l. .P.r.i.n.t.e.r. .2. .d.r.i.v.e.r.". .L.o.g.P.a.t.h.V.a.r.i.a.b.l.e.=.".". .C.o.m.p.r.e.s.s.e.d.=.".n.o.". .I.d.=.".{.7.f.2.f.2.0.0.8.-.2.5.a.0.-.4.3.a.2.-.9.1.1.1.-.b.3.0.b.f.b.b.c.a.0.8.7.}.". .U.p.g.r.a.d.e.C.o.d.e.=.".{.7.C.2.E.7.E.2.2.-.1.2.2.8.-.4.2.4.9.-.A.3.D.A.-.8.1.C.5.6.4.3.8.B.4.9.1.}.". .P.e.r.M.a.c.h.i.n.e.=.".y.e.s.". ./.>..... . .<.W.i.x.P.a.c.k.a.g.e.P.r.o.p.e.r.t.i.e.s. .P.a.c.k.a.g.e.=.".M.S.I.". .V.i.t.a.l.=.".y.e.s.". .D.i.s.p.l.a.y.N.a.m.e.=.".L.e.n.o.v.o. .U.n.i.v.e.r.s.a.l. .P.r.i.n.t.e.r. .2. .d.r.i.v.e.r.". .D.o.w.n.l.o.a.d.S.i.z.e.=.".3.2.7.6.8.". .P.a.c.k.a.g.e.S.i.z.
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):823
                                                                        Entropy (8bit):4.8423972620392846
                                                                        Encrypted:false
                                                                        SSDEEP:12:MMHd41Gqt7lzc+TXYr+XF69bWzc+TXYcXIhuGsVymhsSOJ9OT3XwJwxXPDFWKWGb:Jdi7RtYrx9itYxmhCu3QwxgbLHG3F
                                                                        MD5:5FD9AAB6BDC0C6B916D3433975256D3F
                                                                        SHA1:2AD0A5B57CBC1DB25FC1B387F232F5626C850924
                                                                        SHA-256:DAFF1E8A96D210DCEABD52FF849106E4D78D98DB1C9A7B198C9E81FC604E84F7
                                                                        SHA-512:AE0B0C3CB9B65D336DB2E5E148863AC4BD02DA2DD1BF77E7CD3F9F81E663BFEBDF676EE7DF575114F853D9EB189577824E0516A502E948CD0A9526FFCC80600F
                                                                        Malicious:false
                                                                        Preview:.<?xml version="1.0" encoding="utf-8" ?>..<configuration>.. <configSections>.. <sectionGroup name="wix.bootstrapper" type="Microsoft.Tools.WindowsInstallerXml.Bootstrapper.BootstrapperSectionGroup, BootstrapperCore">.. <section name="host" type="Microsoft.Tools.WindowsInstallerXml.Bootstrapper.HostSection, BootstrapperCore" />.. </sectionGroup>.. </configSections>.. <startup useLegacyV2RuntimeActivationPolicy="true">.. <supportedRuntime version="v4.0" />.. </startup>.. <wix.bootstrapper>.. this probably needs to change to vcredist -->.. <host assemblyName="TAPInstallerNative">.. <supportedFramework version="v4\Full" />.. <supportedFramework version="v4\Client" />.. </host>.. </wix.bootstrapper>..</configuration>..
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):147456
                                                                        Entropy (8bit):6.372962670145268
                                                                        Encrypted:false
                                                                        SSDEEP:3072:Rjvc2Vkb+M8j+Q7esrRUcAXhV7vwJHA7JB/9QPzScHLIiJh4Fs:Rj48xyIUrXhtvwJHA7JB/9QPzScHLIiC
                                                                        MD5:6580F60836F053D208A00466D4D99D30
                                                                        SHA1:93699A54E63B690257A98C6BD03EE90079C2ECFD
                                                                        SHA-256:3F20AEBF0F7250D73B85F72FD56FA11494704C30FDEC16FD7003895D885D7EB8
                                                                        SHA-512:9997B8C242515A2DC2DD1256C93C95A1C13FCEA0C3A8CE16DE7C80722A5D0B8D6BF2EB776FF02BCCA8BA6E7FA144964A2A07B420AACA08951A5943F863374100
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......>.`]z...z...z....2..y....2..v....2..~....2......z...............]1..p...]1..{...]1..{...z...{...]1..{...Richz...................PE..L.....$^...........!.....V..........rF.......p............................................@.........................`....]..T...d....@..`....................P..0....r..8............................{..@............p..`............................text....T.......V.................. ..`.rdata.......p.......Z..............@..@.data........ ......................@....rsrc...`....@......................@..@.reloc..8(...P...*..................@..B........................................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):896000
                                                                        Entropy (8bit):5.916316957560524
                                                                        Encrypted:false
                                                                        SSDEEP:12288:rcDHHV+iXdLoAHVcl4b+CqdZlEvDLHLtQ5hgcu/DmbDEpd5:2HHVxdPHEdbG
                                                                        MD5:B451CA619FC055F907B6E949C74CEAD6
                                                                        SHA1:F59849BEE0A2CF64939B8E41F7916A990ADDDA12
                                                                        SHA-256:C70219828DC39CE91195ACD709F716C12569D47943B393CD39A530329CA1CEA6
                                                                        SHA-512:A2F2E8F0791D330CF5D7DFB4C87D1388341B6C29D550F41FE61895FFBAA9176D7B60055542161FBCEEDCCB352A0443BE22678A9F16DE943C97BBD24E8FECC194
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......................Qy......Qy......Qy......Qy......i.r..............z.......z.......z.......z........\......z......Rich....................PE..L.....$^...........!......................................................................@.............................e......P....p..P........................... ...8............................@..@...................\...@....................text............................... ..`.rdata..............................@..@.data...pN... ...H..................@....rsrc...P....p.......H..............@..@.reloc...\.......^...N..............@..B................................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):184832
                                                                        Entropy (8bit):6.201329128012273
                                                                        Encrypted:false
                                                                        SSDEEP:3072:YgIwWD5OaXEkMVD2YEhxiVYHYKzuXOBHc/VV/YYYhYYYNYYYFJF6wdmqWDbuE9yX:YgpVD2YEhx8VYJowthQkxSC
                                                                        MD5:324A691361D6D1C13818FF15687C8B04
                                                                        SHA1:6FF603093EE8F97EF9CB6633ADC98282ADE09F8B
                                                                        SHA-256:4CE57AECC47C4CF8666EE1CE4423AF1E07FC8DFD97EF2D4BC70DC5E8820F204F
                                                                        SHA-512:AA8F27101D200A50A16A5DD08787DFB89DC54EFA65CCC140A0E571E85D60645F8385315E88A9909A36C74CB18EA1782A09F52E21DC05D76977DD9B4ACA9F4580
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........$)..Jz..Jz..JzZ<.z..JzZ<.z..JzZ<.z..JzZ<.z..Jzb..z..Jzb..z..Jzb..z..Jz.?.z..Jz..KzX.Jz.?.z..Jz.?.z..Jz.?.z..Jz.?.z..Jz.?.z..JzRich..Jz........PE..L.....$^...........!.........6............................................................@..................................|..................................L.......8...........................HW..@...............8............................text............................... ..`.rdata..............................@..@.data...............................@....rsrc...............................@..@.reloc...%.......&..................@..B........................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:Zip archive data, at least v2.0 to extract
                                                                        Category:dropped
                                                                        Size (bytes):1142372
                                                                        Entropy (8bit):7.999561008246305
                                                                        Encrypted:true
                                                                        SSDEEP:24576:wJhCEwIj/4FTIJVbCHzrxL1Jd9jpgna38sc8wCVW6AG1F7q/m/6:wf/jJNCvxvrpg195vFYF7q/e6
                                                                        MD5:C360BE40E96FFA35047C1B2BAE696F39
                                                                        SHA1:F391A32B1B11055EF0A3142B230CE02959AAFBEF
                                                                        SHA-256:48E1F858AE72F49CD15DAB73D9CF414BCDAC63DA28DDA39FD9CC79CA95D06CB1
                                                                        SHA-512:99E6F2083FBA25CBD03CFFE640DEEECD933DC4D1E099F1A26C87C9F366AD07B1E5C8E4FCAEAC7D1B945E26CBD9826A6BC5DA3575238E8FD5272CB60369011678
                                                                        Malicious:false
                                                                        Preview:PK.........d4P8rVy.......7...InstallerPackages/printerinstaller/printerinstaller.zipl..p/O..c;9......m../.m.m.m..}wk.{o.TOuOMMO......m9IP04 (.C-&.ECj......@@...l................2.]...|g...LC..3~.[..!.@C.$}....E.S.;.r.u.m5dr.7...f..... QP.....<........`{.....c..s.=.4Jx.l~yN...L..N..H..I..M.X..}......N9.:u.d....D..HC.z.$HX..<..1......GH.n..0.5=u.y...........{T....2..O.........9.P7&...iz....)....U.ujp....... v...@.~.O..\cp.v...@........7Y..g.<W.Nf.A.t.+N...kW.N..X..k.....{..?..m\$J.%....X.I.0m....h...i..J.. ./o.9.#.m....;.%..D./.....a..f@.i.!....w....mj..qP.{.e.(...T*.1.+..G. Oc......i...t.,.........@......eY..}...3Qp..&.xc...?...G...pl.^>I`x$..?..9`....O..1..:|..s.&z....Z....4)..t;.V.......R....6L.XW...e.&....F..8...g.`......!..\P..=..E...0.....K3.HSU......K..J..s......s.b}c.._.....-....CM.?D+.u..L....'Zq..t.b.G...C|.._......$..UH..g*...-;I.......(s....?..V".J.*...5._\..jz.8+.=......w..d......P..K...z.h..&~o.|.;.(R.....i>.._.!.P.;l
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):74752
                                                                        Entropy (8bit):6.007910841316058
                                                                        Encrypted:false
                                                                        SSDEEP:1536:FIKeyhEcdFgsRv72J5lYglW5zSUlXxLKElv:F/hEcdFgU2JvYgcBLH
                                                                        MD5:B39A1DA587CCD8F44B136F1730839134
                                                                        SHA1:DA6E6D110106C12851A6F0F4BAE318D6F2BEBF8D
                                                                        SHA-256:837990224608D3952B97EA9DAA1B2896632A49D56072B57FEDB87345264856BD
                                                                        SHA-512:0C27DF720033B8C5BB941915DB2CF9C12FB2869BACBA3F23C94F605C7BCB7B250BBDE685CA1842D68D7F807BA730212AD3E815DD8EAE7C62879B5060A7CBF9E1
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........U...4.}.4.}.4.}..x}.4.}..~}.4.}..}}.4.}..|}.4.}..x}.4.}.4.}k4.}9C.}.4.}..|}.4.}..`}.4.}..y}.4.}..z}.4.}.4$}.4.}...}.4.}Rich.4.}................PE..L.....$^...........!.........z...............................................`............@.............................t...4...x.... ..@....................0..........8...............................@............................................text............................... ..`.rdata..tC.......D..................@..@.data...p...........................@....rsrc...@.... ......................@..@.reloc..>"...0...$..................@..B........................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):63488
                                                                        Entropy (8bit):6.023906588407848
                                                                        Encrypted:false
                                                                        SSDEEP:1536:nfPVyPEZ7/Wyjv+1vV7iqb/uB8XNT3Ae:n1flv+1N7jTuyxAe
                                                                        MD5:91FCB46751086ED6B0CE932841216A08
                                                                        SHA1:FA96FA4A3E39F06231C6DE623BE9B46888E89C25
                                                                        SHA-256:B8E9B997D19E17DEB3A07AFF5F56B275F2D21F221E7DF5F61D21BDC8C4E43ED3
                                                                        SHA-512:091467A6612275E65AAA968C68B6064591D85FE3004435E103F3AEBF32D139B17456E771BB91F7CC8AB785D303F64098B91B48235ACB9EC407D0AD1842E881A5
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........K'..%t..%t..%t5/.t..%t5/.t..%t5/.t..%t5/.t..%t.,.t..%t..$t_.%t...t..%t.,.t..%t.,.t..%t.,.t..%t.,.t..%t..t..%t.,.t..%tRich..%t................PE..L.....$^...........!.........f......3........................................ ............@.........................0...v.......d.......@..............................8...............................@............................................text...k........................... ..`.rdata...;.......<..................@..@.data...............................@....rsrc...@...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):205312
                                                                        Entropy (8bit):5.9918310339635985
                                                                        Encrypted:false
                                                                        SSDEEP:3072:lW5T1edDRMu7UMAT1DzyYYYYXSxsEDInG6eH4ZV7AEl/8jQLNhqYH2dJjNc:JFMu704SxsEDv4ZV7AuE0qYHyNc
                                                                        MD5:A6EE1071E9AC47B7DBE707B9C5EDCA2A
                                                                        SHA1:483F899AF3764687CCD2F205A967EBB33CAD7C0E
                                                                        SHA-256:3E497A3B5FDFF2DA7EE8935BEEAF87F6F1FD4E208962B745667B0244310A2B60
                                                                        SHA-512:397FE1A8D73C0CFB2AD2BEF940BE30384BEDB49A66AF01ECFB7FE084DC760248BA46B9D8661661FD07483D7BE58832481DEEC9A2882D9BB8ED6F9D83B6D1A0CB
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......;=...\...\...\....s.}\....p.s\....q.{\....u.{\...+..}\..X.q.|\..X.u.|\...\...\..X.m.|\..X.t.~\..X.w.~\..X.r.~\..Rich.\..........................PE..L.....$^...........!.........................0...............................P............@.................................x...d............................ ...+..04..8........................... ...@............0...............................text............................... ..`.rdata..P....0......................@..@.data...<...........................@....rsrc...............................@..@.reloc.../... ...0..................@..B........................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):385536
                                                                        Entropy (8bit):6.307931095108347
                                                                        Encrypted:false
                                                                        SSDEEP:6144:QQMgk9CE8Hkdqsu8QYf984BwRMfR+98aNQVnaFubm4pOukzrTfYn2:JELmUNoQsFub9pLOTk2
                                                                        MD5:DA228D01E3ABCC0F071B3C17CD7DEC31
                                                                        SHA1:A0E35232597D8F5781F748260E804100C99B2120
                                                                        SHA-256:31D4815EF519160B2A29E39A336557BB1CDB99F827D6370F79CCE0D5E8B9D384
                                                                        SHA-512:82C8865609E2424347DCE4AB1417907F65649A6FEA1298F04257FDD2D2D982E9B99EA184E3BF990413A0716369762B54AD84C53F59EA7B49560C49030BACA876
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......L....ln..ln..ln.....ln.....ln.....ln.....ln./....ln..lo..mn.....ln./....ln./....ln./....ln./....ln..l...ln./....ln.Rich.ln.........PE..L.....$^...........!.....H...................`............................... ............@..........................A..........d.......@.......................|V...e..8...............................@............`..$............................text....G.......H.................. ..`.rdata..s....`.......L..............@..@.data....!...P.......0..............@....rsrc...@............N..............@..@.reloc...............T..............@..B................................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):302592
                                                                        Entropy (8bit):6.328503226917208
                                                                        Encrypted:false
                                                                        SSDEEP:6144:Ppgp9IEbwMayAjWQTnIa7/UBxD5Wv5smh4eMy6Zd2zZTJsmdoX:2pmERAjiH+h4eciTKyoX
                                                                        MD5:8175B2AC653706EC44C9A934A0E2EE7F
                                                                        SHA1:E4BA3AA12E1E12E235DDB96B9D5535589E8FD6A9
                                                                        SHA-256:A131AFB934FCB2B2DEB0CC794C19059D1463B5AA3596E7FF527E968FB4587399
                                                                        SHA-512:AB58F5CBAA3720D356D7C13B77892111B86B2C8A484059367ABBD73FCCC22A830607ADC46DDD36E4B186B1A643DA7E61E426C2DC5D4876AA64E3C592EDE3F8E5
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Y.#]8.p]8.p]8.p..5pY8.p..3p_8.p..0pV8.p..1pX8.pz.5p_8.p]8.pj9.p.OGp^8.pz.1pU8.pz.-pZ8.pz.4p\8.pz.7p\8.p]8ip\8.pz.2p\8.pRich]8.p........PE..L.....$^...........!.....`...>......e........p............................................@.............................x.......d....P..@....................`...G...t..8...........................p...@............p..\............................text....^.......`.................. ..`.rdata.......p.......d..............@..@.data........0.......$..............@....rsrc...@....P.......4..............@..@.reloc...c...`...d...:..............@..B................................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):96768
                                                                        Entropy (8bit):6.108827065206922
                                                                        Encrypted:false
                                                                        SSDEEP:1536:fvYYQBcmBbH7+3lCwfbc+v9lJC27Y6w8timCKq+pK/JYAqnDFLupYEd:fQYKBW3lNfbc+dC286w8timCKq5/JYAh
                                                                        MD5:096656CFA3EBF9DF4C4989D2A13A1FD2
                                                                        SHA1:242BA75AD11C874BBFB0D797A6F2012725AEC785
                                                                        SHA-256:97BB11D3E88D999198D5F3B219F3D6296A58E4BA795EF49222EB0C10FF0510DC
                                                                        SHA-512:1EF8EDBA0383E3B00431ECE694B290556B854A795AE3E550B52D47DE5DE2F5055E343E145BB6A252852B9302C896522293688741A055BBFC7C4C6EC97238D74B
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......!.x.ex.Oex.Oex.O...Oax.O...Ogx.O...Onx.O...Oax.OB..Oax.Oex.O.x.O...O`x.OB..Ofx.OB..Ogx.OB..Odx.OB..Odx.Oex.Odx.OB..Odx.ORichex.O................PE..L.....$^...........!......................................................................@..........................M......8+.......`..@....................p......@...8...............................@............................................text...k........................... ..`.rdata..@N.......P..................@..@.data........P.......@..............@....rsrc...@....`.......J..............@..@.reloc...(...p...*...P..............@..B........................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):228864
                                                                        Entropy (8bit):5.850369037904936
                                                                        Encrypted:false
                                                                        SSDEEP:6144:ARSkHVgLAIupOV4VnKQWqNym+Kv/tv2PcZatuDYI:dkpWqNym+Kv/cPc7
                                                                        MD5:BB9E7C7B816EDF68AAD8A222CB593E55
                                                                        SHA1:A4E55CEF008CF898A06BE4DB7A4084A4BF6842C8
                                                                        SHA-256:F3CB1C2BFBCF08B714B5605A9B1547B38558F337B3DAAFEF00C5E0967DC3C10B
                                                                        SHA-512:A1B48C550537411D64D5B9622AC0F851BEE3CE1E7A079887B6C9F5B9C0A1EDBEFAA4B0EF10B97BA34DFE11BEEDC075966A3BE2BA7346C2A86E919BD3F9284959
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............|..|..|......|......|......|......|.).a..|.....|..|..|.....|.....|.....|.....|.....|.Rich.|.........................PE..L.....$^...........!.....P...................`............................................@..........................6..N............`.......................p...0...c..8...............................@............`...............................text...kN.......P.................. ..`.rdata.......`.......T..............@..@.data...0....P.......6..............@....rsrc........`.......B..............@..@.reloc...8...p...:...D..............@..B........................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):733696
                                                                        Entropy (8bit):6.312276715256071
                                                                        Encrypted:false
                                                                        SSDEEP:12288:ZiqueE+rJsRuobjB04vT/DZtS/TtkjUME:0quejJsgobbb/VQ/TtkjN
                                                                        MD5:2B343FF9C88FD103DABB9E48EEBBD12C
                                                                        SHA1:4DA445BDD3FCEFD928A419C9F64FD9A4CC7C9000
                                                                        SHA-256:66034E9CDCDEB42E7A88B759C53819D070DC31A143160F32B39DC38B45A9ED91
                                                                        SHA-512:DE8EA169F93BBA95B78C7EBEC66B7DA5FBC5DBEE82B97E9451F740D462E2B1C4216FC279FB960B54E0E48BA5733B131CD489E60FEB78B1923679F43FAFDE43B9
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......f2\!"S2r"S2r"S2r..r$S2r..r.S2r..r&S2r..r$S2r...r&S2r...r!S2r"S3r.R2r.$.r%S2r...r5S2r...r#S2r...r#S2r"S.r#S2r...r#S2rRich"S2r........PE..L.....$^...........!.....r................................................................@.........................`.......T........P..@....................`..\...0...8...........................`...@............................................text....p.......r.................. ..`.rdata...h.......j...v..............@..@.data...|@.......6..................@....rsrc...@....P......................@..@.reloc.......`......................@..B................................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):634880
                                                                        Entropy (8bit):6.392103510828345
                                                                        Encrypted:false
                                                                        SSDEEP:6144:qfg1Tu9RsWStOIvmLjOrKv4liYGYbhWIgIOaotxF14xogxOONhnhI0pPQq99G1U1:oXO3fWTp14xlFpfHenkaWbtgFtcz
                                                                        MD5:CF6D9B4C0490401C32C9697A9FFEA0B1
                                                                        SHA1:5B1CF1640795434388E34A9459C10B9969D36706
                                                                        SHA-256:B39B34AF1F7A196F79C03B0F3AC0811A0DD2C4A4A557B8DF1D3C65FBF5C420E0
                                                                        SHA-512:48E2056B20D8BFCE1FE739CDB1C3C2E690A9141F7489262D7700EF29C42B825675CADF13545C481860439FC8818AEF5D72D5F47B29DF71FB4EEB6D5AD752A831
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........[..5..5..5.*....5.*....5.*....5.*....5..|...5..4.=.5.....5..|...5..|...5..|..5..|...5..|...5....5..|...5.Rich.5.........PE..L.....$^...........!................3]....... ............................................@................................0[..........@...........................P'..8...............................@............ ...............................text............................... ..`.rdata...~... ......................@..@.data....5.......0..................@....rsrc...@...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):897536
                                                                        Entropy (8bit):6.640279717775654
                                                                        Encrypted:false
                                                                        SSDEEP:24576:DC/+BHj0T3Sfl0dkHG5WM90wZrCdqnIUwzBVIKH:MGD0T3845xdrCknuzrH
                                                                        MD5:534710756406AFA4390C587F5ADBAB2F
                                                                        SHA1:292B4361D8DB873AD8C9E1A8F92BC10BDC63BC51
                                                                        SHA-256:F471D0A905FBAB6DE1DEF654AC35F135F9C2ABFC355337D7EE0988FE1BC1E450
                                                                        SHA-512:5D785CD44DD9236B61EDDEC1324EF9340DA7C74E29893F5CC6B91C963B46C5F1AD7954A60D0C9059815F81D5BD7665D6397D28D32AA2203A796715902FE22BF0
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........dIDo..Do..Do......@o......Ho......Ho......@o..c...@o..Do...n......Go..c...Oo..c...Vo..c...Eo..c...Eo..Do..Eo..c...Eo..RichDo..........................PE..L.....$^...........!.....8...................P............................................@.....................................x....0..@....................@.......V..8...............................@............P...............................text...[7.......8.................. ..`.rdata.......P.......<..............@..@.data...$E.......(..................@....rsrc...@....0......................@..@.reloc......@......................@..B................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):184320
                                                                        Entropy (8bit):6.338460220635905
                                                                        Encrypted:false
                                                                        SSDEEP:3072:ggh7klzUOCbyvXS2HeBRdtSBusI5AlxmZK8raeA7GyU1U94ECuo74y:ROCbyvRHeRiusI5AjmgOazl94Fy
                                                                        MD5:535A99C81422ED10F1F9ABDC09561B96
                                                                        SHA1:BF8D21808D267500F1966E2177271F4C7C6B9A3C
                                                                        SHA-256:9CFA3D70F1B8D2F07A1431D218F94DE93EA29CB9D4C8A282F44ADE6D737A67DB
                                                                        SHA-512:A9CF99496AEACF3383D6FA9A9A9BC5E13DCB6E951C76BF374F60CE0A42BBCA2A2CCDAFE2E614E04CC7E272D669372CA00468F29369DA1419520B2C5F22AC63D7
                                                                        Malicious:false
                                                                        Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$..........FU..U..U....L.Q....O.^....?.W....J.Q....N.X..r.J.W....=.T..r.N.S..U.......8.F..r.R.W..r.K.T..r.H.T..U...T..r.M.T..RichU..................PE..L.....$^...........!......................................................................@.........................0...n....M..........@........................+......8...............................@............................................text............................... ..`.rdata..............................@..@.data................t..............@....rsrc...@...........................@..@.reloc...F.......H..................@..B........................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):53248
                                                                        Entropy (8bit):5.935607013668494
                                                                        Encrypted:false
                                                                        SSDEEP:768:PangRkxf71JmriLepCofcIIrCExaiNtQGtRBzWaHSYAFxha6HNA3:iEuf76OL4dc0TYAFxEcq3
                                                                        MD5:7698AE83613E9BE54449246D68CE7921
                                                                        SHA1:9FB5325352595FD6D0DA652D90B5F51FA8D59AA4
                                                                        SHA-256:82F2B77F14D8A4003EC8E69A67689848C0417112320F9B8930D089A2BF8BF850
                                                                        SHA-512:DDED165AB205EC88A8CC520089DBF97E988906F69F22D1E8A30B35406C55541D5EDCF225CAAC519D4E08893754BFEC18B5A27C0A594C7F8042BB30D9F75A5FF5
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........M...,.E.,.E.,.EU.BE.,.EU.DE.,.EU.GE.,.EU.FE.,.E..BE.,.E.,.E.,.Em[0E.,.E..FE.,.E..ZE.,.E..CE.,.E..@E.,.E.,.E.,.E..EE.,.ERich.,.E........PE..L.....$^...........!.....r...^.......m....................................................@.............................j.......x.......@.......................P.......8...........................h...@...............h............................text...Kq.......r.................. ..`.rdata..j5.......6...v..............@..@.data...h...........................@....rsrc...@...........................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                        Category:dropped
                                                                        Size (bytes):185344
                                                                        Entropy (8bit):6.054886947299871
                                                                        Encrypted:false
                                                                        SSDEEP:3072:0WG7YGKYYztfCV8NxYYY8Z2M4pZPj2HXOJ4EcMr6qEl6wFTZT:I7k2M4pYHXOKEBFEl6wFT
                                                                        MD5:589077B2F916A936AECC319C2CF25D68
                                                                        SHA1:BB3125DC1482DF3801B9CBEF2982ABDE185EBAA4
                                                                        SHA-256:CC513BD5399ACB4E4B8B692AB1D0B47BC5DA4B091360A19D0F9108C6D33F04E1
                                                                        SHA-512:09820D7CE6EA31DBDCDA78CFF205445EF8527D11C86C45FF66015DA26E5E75437DD59A55A4A9039E8939EDA58A6CD11455CCEDA5F2E2845B9C30719C81818922
                                                                        Malicious:false
                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........U..QU..QU..Q...QS..Q...QX..Q...QQ..Q...QP..Q..mQW..Q..oQT..Qr|.QV..Qr|.Q\..QU..Q...Q..hQ_..Qr|.QT..Qr|.QT..Qr|.QT..Qr|.QT..QRichU..Q........PE..L.....$^...........!.........*...........................................................@.........................p.......(y...................................!......8...........................`I..@............................................text.............................. ..`.rdata..[...........................@..@.data...T...........................@....rsrc...............................@..@.reloc..r).......*..................@..B........................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7976
                                                                        Entropy (8bit):5.021764400443382
                                                                        Encrypted:false
                                                                        SSDEEP:192:wSmkRFXNxKj3e3dC8lswHx1MR1/KQGRtgga36a/0PeawW/huDZCTB:DgEbdHL/xTB
                                                                        MD5:A713D4EB7E8A883D77A07C2857C1C32D
                                                                        SHA1:A8FB7F805029EDA62534A83D7746BA7F47DD7656
                                                                        SHA-256:536E8999F5E79E7A049E6FE6BA28672ABF6422202748210115351B16C8F219C2
                                                                        SHA-512:4632095967D1F97C25B1621DECCA72A60FD56BBE5449EB055DCEDB92444F9A795BFF207498FA5183E8E49F90510968E7630937DF8707A4D2EDE47A0AF521E45A
                                                                        Malicious:false
                                                                        Preview:......................................................................................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):11028
                                                                        Entropy (8bit):6.279529317131457
                                                                        Encrypted:false
                                                                        SSDEEP:192:FPvMXkm8wlq6olDfKyzWeJ1XqsfxvN1SYezRY/p39S:FPkX78wQ6KfKq6sfxvN1SYeKHS
                                                                        MD5:42D85117E4E10F19B1406A5B0F1438B4
                                                                        SHA1:5565AEB3E15D9B4C9A7A990A253AE97EA572E9A8
                                                                        SHA-256:49CCFE4DE5B89337C7CAB256269E852DA104FBE68B78D41175D142EEBE9E6815
                                                                        SHA-512:E782274B36C529B068B3752E321DD1062686DEB2375FAA0CCDC78A60461DCF2F4604B37F9D08678EC9BD2F20A66B1025CA903EC1568C15D1B8E97A9A056F9671
                                                                        Malicious:false
                                                                        Preview:.......................................................................................................................................................................................................(..."....").. ("..").................................................................("..")............................................................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):6075
                                                                        Entropy (8bit):4.991046356348478
                                                                        Encrypted:false
                                                                        SSDEEP:96:Gsf//e/ntmx8RA0r5z8bQhY8m80ERrq6o1da4RTfv9p6X:GsfOvd1lYezRQbp39S
                                                                        MD5:81F662C0CF6FD712F5471EAC27F76D6B
                                                                        SHA1:9A70CDC03416A5F2F8EFEAA7D39B2A3F5352C4E2
                                                                        SHA-256:29BDD9EFE2ABC89B0BF9AD8856BF04223993672CCA9B14FCEF9494021D667874
                                                                        SHA-512:1C0A05FA3219E8D006BA3DE2C116F41211D00CBE971A81E5C15D5A5322650B9B674070E748E7EBA45E36AFD9C09B8E9BA440BA860B53668590360CD35900E801
                                                                        Malicious:false
                                                                        Preview:END USER SOFTWARE LICENSE AGREEMENT....INSTALLING OR OTHERWISE USING THIS SOFTWARE PRODUCT CONSTITUTES YOUR ACCEPTANCE OF THE FOLLOWING TERMS AND CONDITIONS (UNLESS A SEPARATE LICENSE IS PROVIDED BY THE SUPPLIER OF APPLICABLE SOFTWARE IN WHICH CASE SUCH SEPARATE LICENSE SHALL APPLY). IF YOU DO NOT ACCEPT THESE TERMS, YOU MAY NOT INSTALL OR USE THIS SOFTWARE, AND YOU MUST PROMPTLY RETURN THE SOFTWARE TO THE LOCATION WHERE YOU OBTAINED IT.....GRANT OF LICENSE:..This is a legal agreement between you, the end-user ("You"), and Toshiba Tec Corporation ("TTEC"). This software, fonts (including their typefaces) and related documentation ("Software") is licensed for use with TTEC MFP on which it was installed to the designated device you use ("System") in accordance with the terms contained in this License Agreement. The copyright and other intellectual property rights, title and ownership of Software is proprietary and belonging to TTEC and its suppliers. TTEC disclaim responsibility for th
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):38
                                                                        Entropy (8bit):3.8526761974263795
                                                                        Encrypted:false
                                                                        SSDEEP:3:9gTpQcvRs/V:9wpQcvRs/V
                                                                        MD5:3D957EA873C5DE89E664B8037CF61DD7
                                                                        SHA1:501DAEDF69A7B052AA119718874CB51506BF4ACF
                                                                        SHA-256:8609FB87256561CDD294CFCD781B3FFB6CA3FDEE7C5E0A6F691B3A0B3CEC69C1
                                                                        SHA-512:B2CDBC9251FB3FED9B0C6032C455EC82C65792731FE3E711074C4EDDACD927BCD041C79D5A76F13ED647DDA13E0AB5F2DF481D4A24A1B715A66BB43B964846CC
                                                                        Malicious:false
                                                                        Preview:7C2E7E22-1228-4249-A3DA-81C56438B491 .
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):8943
                                                                        Entropy (8bit):4.894279873543899
                                                                        Encrypted:false
                                                                        SSDEEP:192:u82s9EcO9ERK0P1dez/570xog7wf9QbrnOfMDw9PHBBXWqaRtEBzlw4:Z2sVFP1dO5HOwOfnOfMDQPheRtEBzlw4
                                                                        MD5:60DDA5405C2ECFA1DA183B3A1FB7F858
                                                                        SHA1:D8238F859F796D94F960E5D98589518E36F4C8A0
                                                                        SHA-256:092F7C7CAAE60DDAC04AD9E485FAA2D3897862A954D294134EE68DCFD56D5198
                                                                        SHA-512:29CF38633E97C0F47A49D633440E20C972521266EBAFE8F7A8F1052B14CD9203A20F98BC91AEFC97BCB59109E0538664148B6A5CDBBDBE7A3672489331F8B278
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......Dieses Produkt unterliegt den folgenden Begrenzungen und Regeln. Bitte lesen Sie diese Angaben vor der Verwendung durch.......Regeln..======....1. Windows....- Wenn mithilfe von "Point-and-Print" ein auf dem Server installierter Druckertreiber auf einem Client-PC installiert wird und auf dem Client-PC der Standardwert auf der Registerkarte "Allgemein" des Druckertreibers unter "Einstellungen" festgelegt wird, wird er nicht zum Standardwert auf dem Client-PC, auch wenn im Druckertreiber auf dem Server "Normale Einstellungen" ge.ndert wird.....- In Windows 8 (32 Bit) werden die Dialogfelder, die beim Drucken eingeblendet werden (z. B. "Kennwort f.r vertraulichen Druck" und "Abteilungscode") in einem inaktiven Zustand angezeigt. Dies liegt daran, dass die Anwendung in Windows 8 (32 Bit) .ber WOW64 aufgerufen wird. Bitte machen Sie das angezeigte Dialogfeld aktiv, bevor Sie Einstellungen vornehmen.....- Wenn Bilder im Hochformat und Querformat auf den glei
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):9310
                                                                        Entropy (8bit):4.755537580290009
                                                                        Encrypted:false
                                                                        SSDEEP:192:u/Nxg+QUq8DJyjHX8jfq/kbx6Vmk7pk3kcckFsZNTrXkWxetcXo3YnesgTnM3+0B:qNFRnDgDMjfq/SKkhcTUc943EUhRtEkE
                                                                        MD5:F2E3C58DEFF68BC66103EE2572786E2E
                                                                        SHA1:06054AE96510F9356B8ED64177A9AE840CC7E896
                                                                        SHA-256:27179D4A7E606926DD3CCD906531AB9AE617C692FB0977CF783F7C958A1C03AC
                                                                        SHA-512:C51901F15BC1651A81E2D26B89C2D96CE98B790C0D119B9E3F91E98FAF4D039A7359A08B81B6A4D509F3EC170790A360E301E60201EF74C4349D64764D2DCE5B
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......Este producto presenta las restricciones y los problemas siguientes. Les recomendamos leer atentamente este manual antes de usar el producto.......Algunos hechos..==============....1. Windows....- Cuando el controlador de impresora instalado en un servidor se instala en un PC cliente mediante la opci.n "Apuntar e imprimir" y se establece el valor predeterminado en [Configuraci.n] de la pesta.a [General] en el controlador de impresora del PC cliente, no se puede reflejar como predeterminada en el PC cliente incluso aunque se modifique [Configuraci.n normal] en el controlador de impresora del servidor.....- En Windows 8 de 32 bits, los cuadros de di.logo que aparecen al imprimir, como "Contrase.a de Impresi.n privada" y "C.digo de departamento", se muestran en un estado inactivo. Esto se debe a que la aplicaci.n se llama a trav.s de WOW64 en Windows 8 de 32 bits. Antes de modificar la configuraci.n, debe activar el cuadro de di.logo.....- Cuando
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):9504
                                                                        Entropy (8bit):4.824939353364037
                                                                        Encrypted:false
                                                                        SSDEEP:192:uxmp5pHMIrXc2F8Rfuw5RTRBhfOEE9h7gRtE+oGeR:hAIzc2FGt0EE96RtEPTR
                                                                        MD5:9ADFC128252550D8A5C47FB18F0674DD
                                                                        SHA1:CF3D119A9CFB206ECAC6C3B91F6746D80638B4DC
                                                                        SHA-256:EA79DE5A0E98864AC620EF7AAD9B8D8DFD81F037CA5BAF4644E92A972903127D
                                                                        SHA-512:4129EC354AC61CBDCB494E2CB03A49B10426296E9593F1D21A40D7C773941BC69E35873A2912C582E81259D192A38139AEB3BD0B8501FEB28F6021C117905155
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......Ce produit pr.sente les restrictions et probl.mes suivants. Nous vous recommandons de lire attentivement ce manuel avant l'utilisation du produit.......Certains faits..==============....1. Windows....- Lorsqu'un pilote d'imprimante install. sur un serveur est install. sur un ordinateur client . l'aide de "Pointer et imprimer" et que la valeur par d.faut est r.gl.e sur [Param.tres] sur l'onglet [G.n.ral] dans le pilote d'imprimante de l'ordinateur client, il ne peut pas .tre le pilote par d.faut dans l'ordinateur client m.me si l'option [Param.tres normaux] est modifi. dans le pilote d'imprimante du serveur.....- Sous Windows 8 32 bits, les bo.tes de dialogue apparaissaient . l'impression, par ex., "Mot de passe d'impression priv.e" et "Code d.partemental", s'affichent . l'.tat inactif. La raison : l'application est appel.e via WOW64 sous Windows 8 32 bits. Veuillez vous assurer d'activer la bo.te de dialogue avant le param.tre....
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):9332
                                                                        Entropy (8bit):4.695444988317378
                                                                        Encrypted:false
                                                                        SSDEEP:192:unoA7vMTjimkpwxseTEJ4PT66wbRtEmTirG6TB:c37viimqSlu4bIRtEmgd
                                                                        MD5:8FED4FB30916451C8452342A7A9EFA0E
                                                                        SHA1:987F2EEE9245BF61DD646794D137F2D692825F36
                                                                        SHA-256:8BC1CDACE729CD8039A1A7E0C0AE97BD4E48E61BBF5C526AB39292715A307B79
                                                                        SHA-512:F89C406D2A7C1EC191DDF2DD9B4E6B92347039F18080C8DAC7A004CFC6609FFB874A3B388FD7CB029B1D5DDCA7A8B8BD2B6498DC7EE9FE10C153115A19245798
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......Questo prodotto presenta le restrizioni e problemi seguenti. Vi raccomandiamo di leggere attentamente questo manuale prima di utilizzare il prodotto.......Problemi..========....1. Windows....- Quando il driver della stampante installato su un server viene installato su un client PC utilizzando "Seleziona e stampa" e il valore predefinito . impostato su [Impostazioni] nella scheda [Generale] nel driver della stampante nel client PC, questo non pu. essere applicato sul client PC anche se le [Impostazioni normali] vengono modificate nel driver della stampante del server.....- In Windows 8 a 32 bit, le finestre di dialogo sono visualizzate durante la stampa, ad esempio: "Password Stampa riservata" e "Codice reparto" sono visualizzate con stato inattivo. Questo si verifica perch. l'applicazione viene invocata tramite WOW64 in Windows 8 a 32 bit. Rendere attiva la finestra di dialogo visualizzata prima dell'impostazione.....- Quando l'immagine Ritratto (Portr
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):11481
                                                                        Entropy (8bit):5.523047053733657
                                                                        Encrypted:false
                                                                        SSDEEP:192:um87N5g0gJYHqwDbY7kVWRroyFwCgopwcqfTzRtEToGv1HD:xgNOyqwes9CLwcqLzRtETxv1HD
                                                                        MD5:A1CB1C3BD312A16310B3C505F9917DFA
                                                                        SHA1:42B31D3D48C0BBDB371E4859719D43257E8DE734
                                                                        SHA-256:0E0E19CFA99C1C63A4A5A0D86B6E918146E9543C00C96910645A1A61B1E855C8
                                                                        SHA-512:53A572178F16A3E5A397E7F5644606D4200370CFC6CDB07283BBF4FA896FC9C038A13E2165124AFEACD4C4689E270E86B5DCF8FAFA6C8AEB31E15F8B6C53E74C
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018...... .............................................- JBMIA..........................UI...........................UI.............................UI............................................................................................................................................................................................N in 1......................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7713
                                                                        Entropy (8bit):4.7876922129566575
                                                                        Encrypted:false
                                                                        SSDEEP:192:u0TtKCnWYNUdc+M/B+egRdw2d9PMFOqVE4qj4LAQQERtEqEYRHlwl3c/:fKATQd1M4qe4uDERtERqwlq
                                                                        MD5:A0D5DFCCDAED07B8D11788E008DC9BD5
                                                                        SHA1:7AC38900940A625C4D08F703312B458F701F8C4E
                                                                        SHA-256:6CEAF3CDAB08789C99711F2740AED68363D897C8C5C5E4E46C81A2F9539F77F5
                                                                        SHA-512:9835FA31C04EE4C8BA90E29AB219B6F7CBF114236E33060C967F42453D3897232ACE776A75F7D099D2E6BB23EF8B2D791FEF22F895B209A7BF33E1E29EC5E829
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018......This product has the following restrictions and issues. Please be sure to read this before using.......Issues..======....1. Windows....- When a printer driver installed in a server is installed in a client PC using "Point and Print" and the default value is set in [Settings] on the [General] tab in the printer driver of the client PC, it cannot be reflected as a default in the client PC even if [Normal Settings] is changed in the printer driver of the server.....- In Windows 8 32bit, the dialogs popped up at printing, e.g. "Private Print Password" and "Department Code", are displayed in inactive state. This is because the application is called via WOW64 in Windows 8 32 bit. Please make the displayed dialog active before the setting.....- When Portrait and Landscape images exist on the same sheet in "Multiple Pages per Sheet" printing, printing will be performed by reducing, not by rotating the images.....- When an original paper, which contains Portrait
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7469
                                                                        Entropy (8bit):6.1052933449684526
                                                                        Encrypted:false
                                                                        SSDEEP:192:Xqw8x8D9vhnLCkv7mDJpcmZplfAUR+jm1wRtEVoQ8/:aw8x8pJkdNAq4RtEuQ8/
                                                                        MD5:428083071A8D7A6ED6B9F1C257B7F2DE
                                                                        SHA1:6F5D55E9E10A1FDA25CC95AB21BF59ADB8F5EBF9
                                                                        SHA-256:3EFD24134E38A2C69A8F9358860D427E8E1EE6F34CCF5E25AE93D4C885DA0D38
                                                                        SHA-512:53F064D7A6BB576AE5C298DF5158AA495C2D6525ED9AF45C899A7E2FDF792B1C6F632DBCE3A1A489DEB692F2D2111579B5EA66418C32EED04460E2DA59E623C5
                                                                        Malicious:false
                                                                        Preview:...........2510/3518/5018...................................................======....1. Windows....- ... .Point and Print. ................... PC ......... PC ......[..]...[..]...................[....]................. PC ......- . Windows 8 32 .............................................. Windows 8 32 ..... WOW64 ................................- ..................................................- ........................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):7113
                                                                        Entropy (8bit):6.156561195595807
                                                                        Encrypted:false
                                                                        SSDEEP:192:u3s1TqmnOI5ZTNN9yNL3pBLAfeJuRfK2pNKwfRtEZMhO99vy0aMy:CynOq6VAgudRtEZ9G
                                                                        MD5:7C57B6D41CDD3D89389F3FB566392FDC
                                                                        SHA1:2FADAB30D6B41121D22A06D10E7360D0C58EC11E
                                                                        SHA-256:EA39B662A5C7186DCAFB350C3890E0AA2BE76F1AE37957143506238C4B53DA35
                                                                        SHA-512:1B8210BCB164D55B0005342B56313B87D26311E92CBF1CDB1AB5EFA956912F9D51D0E14EDE2A0EDC571ADD008C4E05DAD563F4CCC97850F8EE89D30FD006D814
                                                                        Malicious:false
                                                                        Preview:.Lenovo 2510/3518/5018........................................====....1. Windows....- ............................point and print................................[..]....[..]..................[....].........................- .Windows 8 32.........................................................Windows 8 32......WOW64.......................- ."...."...........................................- ..........................
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):19448
                                                                        Entropy (8bit):5.737099218049259
                                                                        Encrypted:false
                                                                        SSDEEP:384:NoF3Xoypo2SugaOopWjdAoDdCK2TmEwAdmLkL+rR6jaqtmtsLsK8tCSE:6noypowOopWRAo5CtyEwAPSy3mtsLsP+
                                                                        MD5:E94F01EE41832CFB611E57248DAA792A
                                                                        SHA1:4A5FE73A66B5FF0179DFBF4B43C4B9166936854A
                                                                        SHA-256:ECCF1D6EAA9C68097B6FC1CBD888E545A13F7BB4D19759F25F9F8B684F7E8D32
                                                                        SHA-512:2D6E999D8AC01794E4C4926EDD91571A9898A311F23E5D5EAEEB08B4E175EB1787A7E3DF7A4B4597478246A5D666516A23CD97443BC5527CB2CC31D04DACBA9E
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1029..IDS_BACK=$short_key;Zp.t..IDS_BROWSE=Br$short_key;owse.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Look in:..IDS_BROWSEDLGDESCRIPTION=Browse to the destination folder..IDS_BROWSEDLGNEWFOLDERTOOLTIP=Create a new folder..IDS_BROWSEDLGPATHLABEL=$short_key;Folder name:..IDS_BROWSEDLGTITLE=Change destination folder..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Up one level..IDS_BTN_HELP=N.pov.da..IDS_CANCEL=Zru.it..IDS_CANCELDLGTEXT=Jste si jist., .e chcete zru.it instalaci#{DriverName}..IDS_CONFIRM=Potvrdit..IDS_CUSTOMIZEDLGTITLE=Custom Setup..IDS_CustomOutOfDiskSpaceDlgText=Out of Disk Space..IDS_DEFAULTPRINTER=P.ejete si nastavit n.sleduj.c. tisk.rnu jako v.choz.?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=D$short_key;evices on Network..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=The disk space required for the installation of the selected features...IDS_DISKCOSTDLGTEXT
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):18551
                                                                        Entropy (8bit):5.514561345126865
                                                                        Encrypted:false
                                                                        SSDEEP:384:ELowzIUy86gd8gbGa0k+bGibKwe+g2AMIihoq1xFov33bj:wV4YSwaN1PovP
                                                                        MD5:B8496FE358F8C38D5F0383863BE02538
                                                                        SHA1:84E19174345E32AD0551873F623303A1E48E4E52
                                                                        SHA-256:8A6BEF0A34D114935D242EC11ADE90AF56A82335E0F148D335E4F6C4FBE4BE77
                                                                        SHA-512:82DC56F098DB4679BF443FA85D286BE5AB84F0E6BCBBC5FACEAC339A64104CB5B4E8B4124BBE96DA370004AAC3F4059B97BFA6CAD68871A4242BB15A51089080
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1030..IDS_BACK=$short_key;Tilbage..IDS_BROWSE=G$short_key;ennemse.....IDS_BROWSEDLGCOMBOLABEL=$short_key;S.g i:..IDS_BROWSEDLGDESCRIPTION=Gennemse for at finde destinationsmappen...IDS_BROWSEDLGNEWFOLDERTOOLTIP=Opret en ny mappe..IDS_BROWSEDLGPATHLABEL=$short_key;Mappenavn:..IDS_BROWSEDLGTITLE=V.lg en ny destinationsmappe..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Et niveau op..IDS_BTN_HELP=Hj.lp..IDS_CANCEL=Annull.r..IDS_CANCELDLGTEXT=Vil du annullere installationen af #{DriverName}?..IDS_CONFIRM=Bekr.ft..IDS_CUSTOMIZEDLGTITLE=Specialinstallation..IDS_CustomOutOfDiskSpaceDlgText=Der er ikke mere diskplads...IDS_DEFAULTPRINTER= Vil du angive f.lgende printer som standardprinter?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=$short_key;Enheder p. netv.rket..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=Der er ikke nok diskplads til r.dighed til installationen...IDS_DISKCOSTDLG
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):20079
                                                                        Entropy (8bit):5.48758843506506
                                                                        Encrypted:false
                                                                        SSDEEP:384:K/BZLeJ5MgQV0bRtBquRTmnqUkEgLOripVDn:XPh5RWm9a2/Dn
                                                                        MD5:9FE8D13770D7739B0FE4E542739740A9
                                                                        SHA1:8A6325E1D87BD1E2A7053C642ED2DB4E79C52D34
                                                                        SHA-256:885DFED16C877628D036AC02FB2E1310276DE44B4B3304B63802B731183A82F6
                                                                        SHA-512:4B6EAF506409779F0FD5316C1C6E8627CB39FC7BAD9F5E800C28AD20BC2F1AA2CA129DDAE2426D7C61D9D97425242FD975D7D80CEC841454E54E1948EBC33117
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1031..IDS_BACK=$short_key;Zur.ck..IDS_BROWSE=Du$short_key;rchsuchen.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Suchen in:..IDS_BROWSEDLGDESCRIPTION=Zielordner bestimmen...IDS_BROWSEDLGNEWFOLDERTOOLTIP=Neuen Ordner erzeugen..IDS_BROWSEDLGPATHLABEL=$short_key;Ordnername:..IDS_BROWSEDLGTITLE=Aktuellen Zielordner .ndern..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Eine Ebene h.her..IDS_BTN_HELP=Hilfe..IDS_CANCEL=Abbrechen..IDS_CANCELDLGTEXT=Sind Sie sicher, da. Sie die #{DriverName} Installation abbrechen wollen?..IDS_CONFIRM=Best.tigen..IDS_CUSTOMIZEDLGTITLE=Angepasstes Setup..IDS_CustomOutOfDiskSpaceDlgText=Ungen.gender Speicherplatz..IDS_DEFAULTPRINTER=Wollen Sie den nachstehenden Drucker als Standarddrucker einrichten?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=N$short_key;etzwerkger.te..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=Der erforderliche Festplattenplatz f.r die Inst
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):18430
                                                                        Entropy (8bit):5.468730382407463
                                                                        Encrypted:false
                                                                        SSDEEP:384:qQBhbtpuqx1MLpNc2VDLXtUYtEVxtyeCr:9F4L9ntZaVCeCr
                                                                        MD5:20CE477D1E34506783166886CC54C44F
                                                                        SHA1:58A07EDABF365A2B4586232D9F4F9C6F4945A823
                                                                        SHA-256:F0D53511D34D4F44430B520F0988F8D1CA0811866CF1A313D6B650CF682118A7
                                                                        SHA-512:5BB40A7487CB63C472D797E558085D6273DAE85CFA3A60AAF4AA91972F14266026B24843520CC0B7976ED6BC921CD22F24F6C629DFA6F674133E53A6F92FAEF3
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=2057..IDS_BACK=$short_key;Back..IDS_BROWSE=Br$short_key;owse.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Look in:..IDS_BROWSEDLGDESCRIPTION=Browse to the destination folder...IDS_BROWSEDLGNEWFOLDERTOOLTIP=Create New Folder..IDS_BROWSEDLGPATHLABEL=$short_key;Folder name:..IDS_BROWSEDLGTITLE=Change Current Destination Folder..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Up One Level..IDS_BTN_HELP=Help..IDS_CANCEL=Cancel..IDS_CANCELDLGTEXT=Are you sure you want to cancel #{DriverName} installation?..IDS_CONFIRM=Confirm..IDS_CUSTOMIZEDLGTITLE=Custom Setup - Plug-ins..IDS_CustomOutOfDiskSpaceDlgText=Out of Disk Space..IDS_DEFAULTPRINTER=Do you want to set the following Printer as the Default Printer?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=D$short_key;evices on Network..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=The disk space required for the installation of the selected features...IDS_D
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):18536
                                                                        Entropy (8bit):5.463106276458748
                                                                        Encrypted:false
                                                                        SSDEEP:384:kJyWKh0yiYug/DjdAvFpNc2YdNlOKzZLXtUYtEVxayePn:JWKOypRAvFQdNlOKzVtZaVTePn
                                                                        MD5:80DE2B52F01A3F22A4A3509E2C43B615
                                                                        SHA1:60E4D4E9C8B9430FD750626EE0A0F5ED6522E218
                                                                        SHA-256:D92F20BA2ABDC434CB6F7FBF022FC3699202A109D0BEFB72382E884103A27A28
                                                                        SHA-512:50D56391BB942C0A55B82651CD670D239C7572CE48E061BB98C589DEF5A1C3B5CBF18020A271B5FA2F198B7D1A813B43CCBC3040F1100554996A3C4A48A30D43
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1033..IDS_BACK=$short_key;Back..IDS_BROWSE=Br$short_key;owse.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Look in:..IDS_BROWSEDLGDESCRIPTION=Browse to the destination folder..IDS_BROWSEDLGNEWFOLDERTOOLTIP=Create a new folder..IDS_BROWSEDLGPATHLABEL=$short_key;Folder name:..IDS_BROWSEDLGTITLE=Change destination folder..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Up one level..IDS_BTN_HELP=Help..IDS_CANCEL=Cancel..IDS_CANCELDLGTEXT=Are you sure you want to cancel #{DriverName} installation?..IDS_CONFIRM=Confirm..IDS_CUSTOMIZEDLGTITLE=Custom Setup..IDS_CustomOutOfDiskSpaceDlgText=Out of Disk Space..IDS_DEFAULTPRINTER=Do you want to set the following Printer as Default Printer?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=D$short_key;evices on Network..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=The disk space required for the installation of the selected features...IDS_DISKCOSTDLGTEXT=Highlig
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):19733
                                                                        Entropy (8bit):5.46231950903827
                                                                        Encrypted:false
                                                                        SSDEEP:384:DNqn4nO9NUcdFHyimYtJLTxDvCeArN5YbPV7xZHGB6WBOvVnqT9Iy/P:D8HHlRF6rsZWMv1qT9Ii
                                                                        MD5:28DD4CF235B93082C82A210F3122EC6A
                                                                        SHA1:C6831194A38F2B208B03920FA33F5AA8C9902D4C
                                                                        SHA-256:6583A861A92F06DE24953FBA4A8035E20EEBD7BD7E002D0B541D297532EE4402
                                                                        SHA-512:2B6ED334021EC6742D2765668A4FA08CEAC664FE0ACCE23476415ACC55968EDCD76AEA143BB90427D41CAA50032252F49D8E0E881A91EEAFBDEDEF24E2B7CC22
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1034..IDS_BACK=At$short_key;r.s..IDS_BROWSE=E$short_key;xaminar.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Buscar en:..IDS_BROWSEDLGDESCRIPTION=Buscar la carpeta de destino...IDS_BROWSEDLGNEWFOLDERTOOLTIP=Crear nueva carpeta..IDS_BROWSEDLGPATHLABEL=$short_key;Nombre de la carpeta:..IDS_BROWSEDLGTITLE=Cambiar la carpeta de destino actual..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Subir un nivel..IDS_BTN_HELP=Ayuda..IDS_CANCEL=Cancelar..IDS_CANCELDLGTEXT=.Est. seguro de que desea cancelar la instalaci.n de #{DriverName}?..IDS_CONFIRM=Confirmar..IDS_CUSTOMIZEDLGTITLE=Instalaci.n personalizada..IDS_CustomOutOfDiskSpaceDlgText=No hay espacio suficiente en disco..IDS_DEFAULTPRINTER=.Desea definir la siguiente impresora como predeterminada?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=Dispositivos $short_key;en la red..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=El espacio en disco nece
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):18064
                                                                        Entropy (8bit):5.484768602318724
                                                                        Encrypted:false
                                                                        SSDEEP:384:DaOsrWbXIYsF2YOgsO7HsCTDwiOtrNEa/sVRTBWPJ7ho:DbcJD9t4PJ7ho
                                                                        MD5:30CED14459F87080750C2FA424E7E08E
                                                                        SHA1:9571631BD3EC2290534E9384E5DDAB7C1E46C7AF
                                                                        SHA-256:4091E0CCE72CAD7C9C3562B34A84E1B3A18C840C1A5E97C0C5FCD85FCFC2D0B4
                                                                        SHA-512:C27842A54C937548444D9920E5FAF37D8E81955DB56F1BF6BCF2C4ADDDA0D04981697C9133DAE59652949FEB16B17F78F4CAE39F071626F954BB774A43CF035A
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1035..IDS_BACK=Ede$short_key;llinen..IDS_BROWSE=S$short_key;elaa.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Kohde:..IDS_BROWSEDLGDESCRIPTION=Selaa kohdekansioon...IDS_BROWSEDLGNEWFOLDERTOOLTIP=Luo uusi kansio..IDS_BROWSEDLGPATHLABEL=K$short_key;ansion nimi:..IDS_BROWSEDLGTITLE=Vaihda nykyinen kohdekansio..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Avaa yl.kansio..IDS_BTN_HELP=Ohje..IDS_CANCEL=Peruuta..IDS_CANCELDLGTEXT=Haluatko varmasti peruuttaa #{DriverName} Asennuksen?..IDS_CONFIRM=Vahvista..IDS_CUSTOMIZEDLGTITLE=Mukautettu asennus..IDS_CustomOutOfDiskSpaceDlgText=Levytila ei riit...IDS_DEFAULTPRINTER= Haluatko asettaa seuraavan tulostimen oletustulostimeksi?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=V$short_key;erkossa olevat laitteet..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=Levytila ei riit. asennukseen...IDS_DISKCOSTDLGTEXT=Korostettujen osioiden levytila ei riit. valit
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):20402
                                                                        Entropy (8bit):5.508234422683568
                                                                        Encrypted:false
                                                                        SSDEEP:384:a1aS7EyMSDot+QBE4+5ZkZrAUo2GOI7Bi+5PPATw8:aAP0EMRSZrfo24k+5PPATw8
                                                                        MD5:25E390AE127958A40ECE301EDD239EB4
                                                                        SHA1:E11D08976FFB46A132F684DB24475FD40A441A51
                                                                        SHA-256:C37D58123D724C41025A3CFA1E701E9726DCD18E73E1F42FEFB7F688B9DD3624
                                                                        SHA-512:C5CF50340CE2A69142A7B1D4B1F01B142DE5B2A95922E4F1DCFEE4951EC9309973961AE7855F48E5FE75D05BCCD98F38ABD8144B288D25B7AA402C565DEDF3D2
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1036..IDS_BACK=P$short_key;r.c.dent..IDS_BROWSE=P$short_key;arcourir.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Rechercher dans:..IDS_BROWSEDLGDESCRIPTION=Indiquez le dossier cible . utiliser...IDS_BROWSEDLGNEWFOLDERTOOLTIP=Cr.er nouveau dossier..IDS_BROWSEDLGPATHLABEL=$short_key;Nom de dossier:..IDS_BROWSEDLGTITLE=Modification du dossier cible..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Dossier parent..IDS_BTN_HELP=Aide..IDS_CANCEL=Annuler..IDS_CANCELDLGTEXT=Souhaitez-vous vraiment annuler l'installation de #{DriverName} ?..IDS_CONFIRM=Confirmer..IDS_CUSTOMIZEDLGTITLE=Installation personnalis.e..IDS_CustomOutOfDiskSpaceDlgText=Espace disque insuffisant..IDS_DEFAULTPRINTER=Souhaitez-vous utiliser cette imprimante par d.faut ?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=P.riph.riqu$short_key;es en r.seau..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=L'espace disque requis pour l
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):20346
                                                                        Entropy (8bit):5.687574259089617
                                                                        Encrypted:false
                                                                        SSDEEP:384:IeIbjsdJnPugMNZGe8jdAgRpt5LUOjn4LV6dHD2N9Co6pYrUgO1g:vTJn0ZGe8RAgT0OVJCQeUgOu
                                                                        MD5:343B39E383BCA8C983A3F67BACC31FE4
                                                                        SHA1:88D1B3CA55EB79121F318F967C430A85E083CFB5
                                                                        SHA-256:90210603402B29C7F979947D6BA65D753D7FFE6AC91036F06869AAEADFE85105
                                                                        SHA-512:73DAF47B386D26BB2EAC2C02AC5C06FEB22EE46D80AC5014EE6B47DD90626B3AFF7C1F4714ACA4C4C9A77A31E7C6F34ED31F3C7037CFF8D0E720E2E9B3566BBB
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1038..IDS_BACK=$short_key;Vissza..IDS_BROWSE=Br$short_key;owse.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Look in:..IDS_BROWSEDLGDESCRIPTION=Browse to the destination folder..IDS_BROWSEDLGNEWFOLDERTOOLTIP=Create a new folder..IDS_BROWSEDLGPATHLABEL=$short_key;Folder name:..IDS_BROWSEDLGTITLE=Change destination folder..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Up one level..IDS_BTN_HELP=Seg.ts.g..IDS_CANCEL=M.gse..IDS_CANCELDLGTEXT=Val.ban meg szeretn. szak.tani a(z) #{DriverName} telep.t.s.t?..IDS_CONFIRM=Meger.s.t.s..IDS_CUSTOMIZEDLGTITLE=Custom Setup..IDS_CustomOutOfDiskSpaceDlgText=Out of Disk Space..IDS_DEFAULTPRINTER=Szeretn. az al.bbi nyomtat.t alap.rtelmezett nyomtat.k.nt be.ll.tani?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=D$short_key;evices on Network..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=The disk space required for the installation of the select
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):19473
                                                                        Entropy (8bit):5.441384790427315
                                                                        Encrypted:false
                                                                        SSDEEP:384:k9i4ZYAWcPE3l0CXuzard4O94Uu6bBh90UI3RnMpLGRoy9keOR:YV5E10CXbiMYRD9keOR
                                                                        MD5:74E044D788C5A6764AC5AB03D81081A6
                                                                        SHA1:CD5A23A4EB17B86CA80340CE814F8BFA2ABB4907
                                                                        SHA-256:A3B0A8E5560B47EF09F41C122C1992C5922B94290CA5BC9555A39A407A543942
                                                                        SHA-512:54ACEF2EEC6F0AD4BB6DE111C109023E03A62AA29424DABFB101ECE61720877AD99E44E43A3451B433869965379C5407AB770EE3FB2A342FDC1BAB20BB970C31
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1040..IDS_BACK=Indiet$short_key;ro..IDS_BROWSE=S$short_key;foglia.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Cerca in:..IDS_BROWSEDLGDESCRIPTION=Consente di selezionare manualmente la cartella di destinazione...IDS_BROWSEDLGNEWFOLDERTOOLTIP=Crea nuova cartella..IDS_BROWSEDLGPATHLABEL=$short_key;Nome cartella:..IDS_BROWSEDLGTITLE=Cambia la cartella corrente di destinazione..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Cartella superiore..IDS_BTN_HELP=Guida..IDS_CANCEL=Annulla..IDS_CANCELDLGTEXT=Annullare l'installazione di #{DriverName}?..IDS_CONFIRM=Conferma..IDS_CUSTOMIZEDLGTITLE=Installazione personalizzata..IDS_CustomOutOfDiskSpaceDlgText=Spazio su disco esaurito..IDS_DEFAULTPRINTER=Si desidera impostare la seguente stampante come Stampante predefinita?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=P$short_key;eriferiche in rete..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=L'installazio
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):23681
                                                                        Entropy (8bit):5.935040402232507
                                                                        Encrypted:false
                                                                        SSDEEP:384:zN23l9cI/gxkOHT23Eov23QRG2IuMThphytJeCOnG5U/g9hygF7gSnSqnj4pV:Z2bcL2N2gRG2DMThcsnG5XoV
                                                                        MD5:B8D1815D810ACACC4E69B2A040A4FA29
                                                                        SHA1:05E8CF3EBAA2CC7B9D5564E9D0B8C45F8A03F9A4
                                                                        SHA-256:03B34A0D1ECA01F16E28F168956233B33AA6DA5BA05116B44E00E2B6E3BBFB6E
                                                                        SHA-512:537A243C67AE3748427D9B152F35ABCD54250AB1E0AB847C5D1A4A88FD0DC367CB5C08318FC8EE6DBC10B37B343ADF7A93ED9B83EFE7855BDE13E31A54E8C590
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1041..IDS_BACK=..($short_key;B)..IDS_BROWSE=..($short_key;O).....IDS_BROWSEDLGCOMBOLABEL=....($short_key;L):..IDS_BROWSEDLGDESCRIPTION=.......................IDS_BROWSEDLGNEWFOLDERTOOLTIP=...........IDS_BROWSEDLGPATHLABEL=.....($short_key;F):..IDS_BROWSEDLGTITLE=................IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=1...........IDS_BTN_HELP=.....IDS_CANCEL=.......IDS_CANCELDLGTEXT=#{DriverName} .................... ?..IDS_CONFIRM=....IDS_CUSTOMIZEDLGTITLE=.... ........IDS_CustomOutOfDiskSpaceDlgText=.............IDS_DEFAULTPRINTER=.......................\n#{DriverName}..IDS_DEVICES_ON_NETWORK=..........($short_key;E).
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):19567
                                                                        Entropy (8bit):5.450032765690142
                                                                        Encrypted:false
                                                                        SSDEEP:384:Fru1lwnSigSzv0dS3pLETtlzRoMXgYzYUU:EqiQ6tdRPO
                                                                        MD5:D459365383CFF4C2F4778525AA68ADD1
                                                                        SHA1:31C58FBD241F4BF6FE6665B4266D38214B213E4E
                                                                        SHA-256:E32E62DA83A85BF1791D870EA170EA465C1D7375B42499DEB69F41A68348418D
                                                                        SHA-512:A1A4637398CC9016542927BF8F30B4D63D1C498D75C80A88BB73FE9DEF5103E48927F3D1DAD92730F6BD990D7728260B16941EA0250B9ECEB5A5EC5F72F621F2
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1043..IDS_BACK=$short_key;Vorige..IDS_BROWSE=$short_key;Bladeren.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Zoeken in:..IDS_BROWSEDLGDESCRIPTION=Bladeren om de doelmap te vinden...IDS_BROWSEDLGNEWFOLDERTOOLTIP=Nieuwe map maken..IDS_BROWSEDLGPATHLABEL=$short_key;Naam van map:..IDS_BROWSEDLGTITLE=Huidige doelmap wijzigen..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=E.n niveau hoger..IDS_BTN_HELP=Help..IDS_CANCEL=Annuleren..IDS_CANCELDLGTEXT=Weet u zeker dat u de installatie van #{DriverName} wilt annuleren?..IDS_CONFIRM=Bevestigen..IDS_CUSTOMIZEDLGTITLE=Aangepaste setup..IDS_CustomOutOfDiskSpaceDlgText=Onvoldoende schijfruimte..IDS_DEFAULTPRINTER=Wilt u de volgende printer als standaard printer gebruiken?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=Apparat$short_key;en op het netwerk..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=De schijfruimte die nodig is voor de installatie overschrijd
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):18524
                                                                        Entropy (8bit):5.495141016347509
                                                                        Encrypted:false
                                                                        SSDEEP:384:y8gGtm1FKyEt9Z6mp5myp2KzcYMVk9PCAS2AOnjRoAt4RZ:y8XE1oyMXzkyzCgjCAt4RZ
                                                                        MD5:7D3E2B6916D14C022730C2C59917598D
                                                                        SHA1:5726EE5CC8E4ED33F75225625CB04DBE50665DA3
                                                                        SHA-256:B6E076E91EB72198BB16D76B5A67143505EF78161FC02E0A49E9F14EDD718240
                                                                        SHA-512:F776F3A6B411F18ACF6E51303C46124BB5E7B3CB18583E1940EA1F2A7C4A411A621B7571C1B10346B4CFFE076FA0D44CAD5548CD76D2D5F3B65EDE59B9C38939
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1044..IDS_BACK=$short_key;Tilbake..IDS_BROWSE=$short_key;Bla gjennom.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Let i:..IDS_BROWSEDLGDESCRIPTION=Bla til m.lmappe...IDS_BROWSEDLGNEWFOLDERTOOLTIP=Lag ny mappe..IDS_BROWSEDLGPATHLABEL=$short_key;Mappenavn:..IDS_BROWSEDLGTITLE=Endre gjeldende m.lmappe..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Opp ett niv...IDS_BTN_HELP=Hjelp..IDS_CANCEL=Avbryt..IDS_CANCELDLGTEXT=Er du sikker p. at du vil avbryte installeringen av #{DriverName}?..IDS_CONFIRM=Bekreft..IDS_CUSTOMIZEDLGTITLE=Tilpasset installering..IDS_CustomOutOfDiskSpaceDlgText=Ikke nok diskplass..IDS_DEFAULTPRINTER=.nsker du . sette denne som standard printer?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=$short_key;Enheter i Nettverket..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=Diskplassen som er n.dvendig for installeringen er st.rre enn tilgjengelig diskplass...IDS_DISKCOSTDLGTE
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):19827
                                                                        Entropy (8bit):5.7478746276594705
                                                                        Encrypted:false
                                                                        SSDEEP:384:X3hz7I4Y8iKyFJfGFn3eqorRwo391NSG1eO05m01lWTEz1+dQXbbobtW0xA4B0N:X3506iKW+FurRwo3vNSGck01lWzdQLb/
                                                                        MD5:68377503C33075C008D5300B98D605EE
                                                                        SHA1:2E620F498265B91F5CFA4FD7A098A4A55E39B1B4
                                                                        SHA-256:F2D6A21350AEC31A1CDBE6BB75DB7C806E4585EF9DA3FB7FBC432737C06CE7BD
                                                                        SHA-512:52D5B44DC83A1AF92BE30EDFC6C08682F9B55D265A90D430531CBD544E860B63C60F57800B1DF38263E81715CAEE1F5EE9793242DFB4A97618E69060736CE59F
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1045..IDS_BACK=$short_key;Wstecz..IDS_BROWSE=P$short_key;rzegl.daj.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Szukaj w:..IDS_BROWSEDLGDESCRIPTION=Wybierz folder docelowy...IDS_BROWSEDLGNEWFOLDERTOOLTIP=Utw.rz nowy folder..IDS_BROWSEDLGPATHLABEL=$short_key;Nazwa folderu:..IDS_BROWSEDLGTITLE=Zmie. aktualny folder docelowy..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Do g.ry o jeden poziom..IDS_BTN_HELP=Pomoc..IDS_CANCEL=Anuluj..IDS_CANCELDLGTEXT=Czy na pewno chcesz anulowa. instalacj. programu #{DriverName}?..IDS_CONFIRM=Potwierd...IDS_CUSTOMIZEDLGTITLE=Instalacja niestandardowa..IDS_CustomOutOfDiskSpaceDlgText=Brak miejsca na dysku..IDS_DEFAULTPRINTER=Czy ustawi. nast.puj.c. drukark. jako drukark. domy.ln.?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=Urz.dz$short_key;enia w sieci..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=Ilo.. wolnego miejsca na dysku jest niewystarc
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):19670
                                                                        Entropy (8bit):5.50930793714747
                                                                        Encrypted:false
                                                                        SSDEEP:384:shElKc+xyorUnap/7wugLlhmNg9KnKjdA/SE76TnnkwqxALDxM/uLOum0xQZY+V3:UEIc+xyorUa6hmNyRA/SE7AnnvqQamLa
                                                                        MD5:673A6602C057D62AF25DD9F3B2C41209
                                                                        SHA1:06F4F2698D69835235968F2739803A383E9DC8F5
                                                                        SHA-256:A2683999986B2E8EC13CB7CBEA7B4A2FA730871E0F77CD9F80B8D2005C3764DD
                                                                        SHA-512:90925A482E677E84853A42B584407438F533BED91C82607F995BF3978324ED93CD574410E51BDB503845AF737E51C67C700CFAEBA12263887F7E1DECCCC362EB
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1046..IDS_BACK=$short_key;Retroceder..IDS_BROWSE=Br$short_key;owse.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Look in:..IDS_BROWSEDLGDESCRIPTION=Browse to the destination folder..IDS_BROWSEDLGNEWFOLDERTOOLTIP=Create a new folder..IDS_BROWSEDLGPATHLABEL=$short_key;Folder name:..IDS_BROWSEDLGTITLE=Change destination folder..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Up one level..IDS_BTN_HELP=Ajuda..IDS_CANCEL=Cancelar..IDS_CANCELDLGTEXT=Tem certeza de que pretende cancelar a instala..o do #{DriverName}..IDS_CONFIRM=Confirmar..IDS_CUSTOMIZEDLGTITLE=Custom Setup..IDS_CustomOutOfDiskSpaceDlgText=Out of Disk Space..IDS_DEFAULTPRINTER=Pretende configurar a seguinte Impressora como impressora predefinida?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=D$short_key;evices on Network..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=The disk space required for the installation of the selected features
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):19612
                                                                        Entropy (8bit):5.510871215744598
                                                                        Encrypted:false
                                                                        SSDEEP:384:WhElKcIxyorUnap/7wugLlhmNg9KnKjdA/QE76TnnkRqxALDxM/uLOum0xbZY+V3:qEIcIxyorUa6hmNyRA/QE7Ann8qQamLL
                                                                        MD5:BE21D3B5FC643C75B1272E9F11A3A444
                                                                        SHA1:55C79DEC64608BBDF15210A69568B5A5C9261F2E
                                                                        SHA-256:73CD9832FBEA40912C490D971BC99EFACF76DB9F1E80204FD150FA26CE9B819A
                                                                        SHA-512:1B40A83F9D96DAB7B6F4573619AD51ADCAB0FE3BE1C78A0DF338B7FAACD2B8BE3276AE58E95829AA858EE01798B42119F3E2A19630D53FBD3B70B8015ADF41D8
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=2070..IDS_BACK=$short_key;Retroceder..IDS_BROWSE=Br$short_key;owse.....IDS_BROWSEDLGCOMBOLABEL=$short_key;Look in:..IDS_BROWSEDLGDESCRIPTION=Browse to the destination folder..IDS_BROWSEDLGNEWFOLDERTOOLTIP=Create a new folder..IDS_BROWSEDLGPATHLABEL=$short_key;Folder name:..IDS_BROWSEDLGTITLE=Change destination folder..IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=Up one level..IDS_BTN_HELP=Ajuda..IDS_CANCEL=Cancelar..IDS_CANCELDLGTEXT=Tem certeza de que pretende cancelar a instala..o do #{DriverName}..IDS_CONFIRM=Confirmar..IDS_CUSTOMIZEDLGTITLE=Custom Setup..IDS_CustomOutOfDiskSpaceDlgText=Out of Disk Space..IDS_DEFAULTPRINTER=Pretende configurar a seguinte Impressora como impressora predefinida?\n#{DriverName}..IDS_DEVICES_ON_NETWORK=D$short_key;evices on Network..IDS_DEVICESETTINGS=Device Settings App and Context Menu..IDS_DISKCOSTDLGDESCRIPTION=The disk space required for the installation of the selected features
                                                                        Process:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):26607
                                                                        Entropy (8bit):5.369266558114818
                                                                        Encrypted:false
                                                                        SSDEEP:384:m5hmi3ywI87+ZjZhXjdJRCBI0Cy57k2OKXj:m/i4iZjZZwFl7fXj
                                                                        MD5:B95181B93878D34510C4B17402E2F559
                                                                        SHA1:EFC3398C2DEBB70BC2E802AB3F82502115FA9FD4
                                                                        SHA-256:C279BE0DFCCF5B089EA0B570A59125986213A0CF90B0839849DAB18653EAEAD1
                                                                        SHA-512:2A29E8F8F57F620CAD14E30FC50B1235707D3957DEC04AD36AF1CAF9739F39085F05CF24DBD78AC404CFF78BBE32EB9F6CA7C386A53D160F9FD0BA3D5B069266
                                                                        Malicious:false
                                                                        Preview:.Localization_Version=122.000..Excel_Spreadsheet_Format_Version=19.08.26..LANG=1049..IDS_BACK=$short_key;.......IDS_BROWSE=$short_key;..........IDS_BROWSEDLGCOMBOLABEL=$short_key;..... . .....:..IDS_BROWSEDLGDESCRIPTION=......... . ..... .............IDS_BROWSEDLGNEWFOLDERTOOLTIP=....... ..... .......IDS_BROWSEDLGPATHLABEL=$short_key;... .....:..IDS_BROWSEDLGTITLE=......... ....... ..... ............IDS_BROWSEDLGWIXUI_BMP_UPTOOLTIP=....... .. .... ....... .......IDS_BTN_HELP=.........IDS_CANCEL=........IDS_CANCELDLGTEXT=........ ......... #{DriverName}?..IDS_CONFIRM=...............IDS_CUSTOMIZEDLGTITLE=.......... ...........IDS_CustomOutOfDiskSpaceDlgText=.. ....... ..... .. .......IDS_DEFAULTPRINTER=.. ...... ......... ......... ....... ....
                                                                        File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                        Entropy (8bit):7.996631073155322
                                                                        TrID:
                                                                        • Win32 Executable (generic) a (10002005/4) 99.96%
                                                                        • Generic Win/DOS Executable (2004/3) 0.02%
                                                                        • DOS Executable Generic (2002/1) 0.02%
                                                                        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                        File name:LMSetup.exe
                                                                        File size:49224728
                                                                        MD5:c915a8370a016f079adfea57cc00b46f
                                                                        SHA1:07b31c5bcad7bc0e9da24a46f180001709e1dbe5
                                                                        SHA256:315d36c57e181df7ee2730361847fb4311eef889df19c2ba8bd00759c46465e5
                                                                        SHA512:b88c8f671aa162668577c214d7a263c7d6f5ec5650e219b9e60e31b43495f6606e9adc9ed03a3db59f148b74bd6a57fc3a36ce2de0349a59545bea9705922f95
                                                                        SSDEEP:786432:CEr3Kc11LDe/4FR2GhrfiCcDZ7y0vMudP4MqF8xs24SIfdZh3Y3TdBpE63pI3mUV:1KqA/4FRnUCcDk2PmNx1w7WmUEk
                                                                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A!.S.@...@...@.......@......y@.......@..."|..@..."{..@..."z.#@...8...@...8...@...@~.PA...#z.N@...#...@...@...@...#}..@..Rich.@.
                                                                        Icon Hash:dcdcceded4d4d4c4
                                                                        Entrypoint:0x42e2a6
                                                                        Entrypoint Section:.text
                                                                        Digitally signed:true
                                                                        Imagebase:0x400000
                                                                        Subsystem:windows gui
                                                                        Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
                                                                        DLL Characteristics:TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                                                                        Time Stamp:0x5A10AD86 [Sat Nov 18 22:00:38 2017 UTC]
                                                                        TLS Callbacks:
                                                                        CLR (.Net) Version:
                                                                        OS Version Major:5
                                                                        OS Version Minor:1
                                                                        File Version Major:5
                                                                        File Version Minor:1
                                                                        Subsystem Version Major:5
                                                                        Subsystem Version Minor:1
                                                                        Import Hash:d7e2fd259780271687ffca462b9e69b7
                                                                        Signature Valid:true
                                                                        Signature Issuer:CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US
                                                                        Signature Validation Error:The operation completed successfully
                                                                        Error Number:0
                                                                        Not Before, Not After
                                                                        • 10/30/2019 5:00:00 PM 10/30/2020 4:59:59 PM
                                                                        Subject Chain
                                                                        • CN=Toshiba Tec Corporation, OU=Solution Design Dept 1, O=Toshiba Tec Corporation, L=Shinagawa-ku, S=Tokyo, C=JP
                                                                        Version:3
                                                                        Thumbprint MD5:611783128FBC54307F929EF62774D416
                                                                        Thumbprint SHA-1:BEAA872989B75F3B3CA92C03AFEA85EF28ADC2D9
                                                                        Thumbprint SHA-256:41FD0DFDD309E9FCDD2BD56721705CD45C6BA536538890334A63FDB9B43D7647
                                                                        Serial:7EDF80DB761DCE3989C9B7EAD9E4D19F
                                                                        Instruction
                                                                        call 00007F0FA8EC5EDFh
                                                                        jmp 00007F0FA8EC5853h
                                                                        mov eax, dword ptr [esp+08h]
                                                                        mov ecx, dword ptr [esp+10h]
                                                                        or ecx, eax
                                                                        mov ecx, dword ptr [esp+0Ch]
                                                                        jne 00007F0FA8EC59CBh
                                                                        mov eax, dword ptr [esp+04h]
                                                                        mul ecx
                                                                        retn 0010h
                                                                        push ebx
                                                                        mul ecx
                                                                        mov ebx, eax
                                                                        mov eax, dword ptr [esp+08h]
                                                                        mul dword ptr [esp+14h]
                                                                        add ebx, eax
                                                                        mov eax, dword ptr [esp+08h]
                                                                        mul ecx
                                                                        add edx, ebx
                                                                        pop ebx
                                                                        retn 0010h
                                                                        int3
                                                                        int3
                                                                        int3
                                                                        int3
                                                                        int3
                                                                        int3
                                                                        int3
                                                                        int3
                                                                        int3
                                                                        int3
                                                                        int3
                                                                        int3
                                                                        cmp cl, 00000040h
                                                                        jnc 00007F0FA8EC59D7h
                                                                        cmp cl, 00000020h
                                                                        jnc 00007F0FA8EC59C8h
                                                                        shrd eax, edx, cl
                                                                        shr edx, cl
                                                                        ret
                                                                        mov eax, edx
                                                                        xor edx, edx
                                                                        and cl, 0000001Fh
                                                                        shr eax, cl
                                                                        ret
                                                                        xor eax, eax
                                                                        xor edx, edx
                                                                        ret
                                                                        push ebp
                                                                        mov ebp, esp
                                                                        jmp 00007F0FA8EC59CFh
                                                                        push dword ptr [ebp+08h]
                                                                        call 00007F0FA8ECC24Ch
                                                                        pop ecx
                                                                        test eax, eax
                                                                        je 00007F0FA8EC59D1h
                                                                        push dword ptr [ebp+08h]
                                                                        call 00007F0FA8ECC2D5h
                                                                        pop ecx
                                                                        test eax, eax
                                                                        je 00007F0FA8EC59A8h
                                                                        pop ebp
                                                                        ret
                                                                        cmp dword ptr [ebp+08h], FFFFFFFFh
                                                                        je 00007F0FA8EC6264h
                                                                        jmp 00007F0FA8EC6241h
                                                                        push ebp
                                                                        mov ebp, esp
                                                                        push dword ptr [ebp+08h]
                                                                        call 00007F0FA8EC627Dh
                                                                        pop ecx
                                                                        pop ebp
                                                                        ret
                                                                        push ebp
                                                                        mov ebp, esp
                                                                        test byte ptr [ebp+08h], 00000001h
                                                                        push esi
                                                                        mov esi, ecx
                                                                        mov dword ptr [esi], 00460DB8h
                                                                        je 00007F0FA8EC59CCh
                                                                        push 0000000Ch
                                                                        push esi
                                                                        call 00007F0FA8EC599Dh
                                                                        pop ecx
                                                                        pop ecx
                                                                        mov eax, esi
                                                                        pop esi
                                                                        pop ebp
                                                                        Programming Language:
                                                                        • [ C ] VS2008 SP1 build 30729
                                                                        • [IMP] VS2008 SP1 build 30729
                                                                        NameVirtual AddressVirtual Size Is in Section
                                                                        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                        IMAGE_DIRECTORY_ENTRY_IMPORT0x686b40xb4.rdata
                                                                        IMAGE_DIRECTORY_ENTRY_RESOURCE0x6d0000x25610.rsrc
                                                                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                        IMAGE_DIRECTORY_ENTRY_SECURITY0x2eeff880x1c90
                                                                        IMAGE_DIRECTORY_ENTRY_BASERELOC0x930000x3dfc.reloc
                                                                        IMAGE_DIRECTORY_ENTRY_DEBUG0x676500x54.rdata
                                                                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                        IMAGE_DIRECTORY_ENTRY_TLS0x676a40x18.rdata
                                                                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x670300x40.rdata
                                                                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                        IMAGE_DIRECTORY_ENTRY_IAT0x4b0000x3e0.rdata
                                                                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x682340x100.rdata
                                                                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                        NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                        .text0x10000x499370x49a00False0.531468856112data6.57000604641IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                                                                        .rdata0x4b0000x1ed600x1ee00False0.313638663968data5.11422830126IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                        .data0x6a0000x17300xa00False0.274609375data3.15265940276IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                                                                        .wixburn0x6c0000x380x200False0.12890625data0.749962524453IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                        .rsrc0x6d0000x256100x25800False0.0701888020833data3.03595133921IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                        .reloc0x930000x3dfc0x3e00False0.809727822581data6.79433546957IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                        NameRVASizeTypeLanguageCountry
                                                                        RT_ICON0x6d3b80xca3PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States
                                                                        RT_ICON0x6e05c0x10828dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                                                        RT_ICON0x7e8840x4c28dataEnglishUnited States
                                                                        RT_ICON0x834ac0x4228dataEnglishUnited States
                                                                        RT_ICON0x876d40x1628dBase IV DBT of \200.DBF, blocks size 0, block length 8192, next free block index 40EnglishUnited States
                                                                        RT_ICON0x88cfc0x25a8dBase IV DBT of `.DBF, block length 18432, next free block index 40EnglishUnited States
                                                                        RT_ICON0x8b2a40xea8dBase IV DBT of `.DBF, block length 4608, next free block index 40EnglishUnited States
                                                                        RT_ICON0x8c14c0x10a8dBase IV DBT of @.DBF, block length 8192, next free block index 40EnglishUnited States
                                                                        RT_ICON0x8d1f40x8a8dBase IV DBT of @.DBF, block length 2048, next free block index 40, next free block 0, next used block 0EnglishUnited States
                                                                        RT_ICON0x8da9c0x988dBase IV DBT of 0.DBF, block length 4608, next free block index 40EnglishUnited States
                                                                        RT_ICON0x8e4240x6c8dataEnglishUnited States
                                                                        RT_ICON0x8eaec0x468GLS_BINARY_LSB_FIRSTEnglishUnited States
                                                                        RT_ICON0x8ef540x568GLS_BINARY_LSB_FIRSTEnglishUnited States
                                                                        RT_MESSAGETABLE0x8f4bc0x2840dataEnglishUnited States
                                                                        RT_GROUP_ICON0x91cfc0xbcdataEnglishUnited States
                                                                        RT_VERSION0x91db80x384dataEnglishUnited States
                                                                        RT_MANIFEST0x9213c0x4d2XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminatorsEnglishUnited States
                                                                        DLLImport
                                                                        ADVAPI32.dllRegCloseKey, RegOpenKeyExW, OpenProcessToken, AdjustTokenPrivileges, LookupPrivilegeValueW, InitiateSystemShutdownExW, GetUserNameW, RegQueryValueExW, RegDeleteValueW, CloseEventLog, OpenEventLogW, ReportEventW, ConvertStringSecurityDescriptorToSecurityDescriptorW, DecryptFileW, CreateWellKnownSid, InitializeAcl, SetEntriesInAclW, ChangeServiceConfigW, CloseServiceHandle, ControlService, OpenSCManagerW, OpenServiceW, QueryServiceStatus, SetNamedSecurityInfoW, CheckTokenMembership, AllocateAndInitializeSid, SetEntriesInAclA, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, RegSetValueExW, RegQueryInfoKeyW, RegEnumValueW, RegEnumKeyExW, RegDeleteKeyW, RegCreateKeyExW, GetTokenInformation, CryptDestroyHash, CryptHashData, CryptCreateHash, CryptGetHashParam, CryptReleaseContext, CryptAcquireContextW, QueryServiceConfigW
                                                                        USER32.dllPeekMessageW, PostMessageW, IsWindow, WaitForInputIdle, PostQuitMessage, GetMessageW, TranslateMessage, MsgWaitForMultipleObjects, PostThreadMessageW, GetMonitorInfoW, MonitorFromPoint, IsDialogMessageW, LoadCursorW, LoadBitmapW, SetWindowLongW, GetWindowLongW, GetCursorPos, MessageBoxW, CreateWindowExW, UnregisterClassW, RegisterClassW, DefWindowProcW, DispatchMessageW
                                                                        OLEAUT32.dllVariantInit, SysAllocString, VariantClear, SysFreeString
                                                                        GDI32.dllDeleteDC, DeleteObject, SelectObject, StretchBlt, GetObjectW, CreateCompatibleDC
                                                                        SHELL32.dllCommandLineToArgvW, SHGetFolderPathW, ShellExecuteExW
                                                                        ole32.dllCoUninitialize, CoInitializeEx, CoInitialize, StringFromGUID2, CoCreateInstance, CoTaskMemFree, CLSIDFromProgID, CoInitializeSecurity
                                                                        KERNEL32.dllGetCommandLineA, GetCPInfo, GetOEMCP, CloseHandle, CreateFileW, GetProcAddress, LocalFree, HeapSetInformation, GetLastError, GetModuleHandleW, FormatMessageW, lstrlenA, lstrlenW, MultiByteToWideChar, WideCharToMultiByte, LCMapStringW, Sleep, GetLocalTime, GetModuleFileNameW, ExpandEnvironmentStringsW, GetTempPathW, GetTempFileNameW, CreateDirectoryW, GetFullPathNameW, CompareStringW, GetCurrentProcessId, WriteFile, SetFilePointer, LoadLibraryW, GetSystemDirectoryW, CreateFileA, HeapAlloc, HeapReAlloc, HeapFree, HeapSize, GetProcessHeap, FindClose, GetCommandLineW, GetCurrentDirectoryW, RemoveDirectoryW, SetFileAttributesW, GetFileAttributesW, DeleteFileW, FindFirstFileW, FindNextFileW, MoveFileExW, GetCurrentProcess, GetCurrentThreadId, InitializeCriticalSection, DeleteCriticalSection, ReleaseMutex, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, CreateProcessW, GetVersionExW, VerSetConditionMask, FreeLibrary, EnterCriticalSection, LeaveCriticalSection, GetSystemTime, GetNativeSystemInfo, GetModuleHandleExW, GetWindowsDirectoryW, GetSystemWow64DirectoryW, GetEnvironmentStringsW, VerifyVersionInfoW, GetVolumePathNameW, GetDateFormatW, GetUserDefaultUILanguage, GetSystemDefaultLangID, GetUserDefaultLangID, GetStringTypeW, ReadFile, SetFilePointerEx, DuplicateHandle, InterlockedExchange, InterlockedCompareExchange, LoadLibraryExW, CreateEventW, ProcessIdToSessionId, OpenProcess, GetProcessId, WaitForSingleObject, ConnectNamedPipe, SetNamedPipeHandleState, CreateNamedPipeW, CreateThread, GetExitCodeThread, SetEvent, WaitForMultipleObjects, InterlockedIncrement, InterlockedDecrement, ResetEvent, SetEndOfFile, SetFileTime, LocalFileTimeToFileTime, DosDateTimeToFileTime, CompareStringA, GetExitCodeProcess, SetThreadExecutionState, CopyFileExW, MapViewOfFile, UnmapViewOfFile, CreateMutexW, CreateFileMappingW, GetThreadLocale, IsValidCodePage, FindFirstFileExW, FreeEnvironmentStringsW, SetStdHandle, GetConsoleCP, GetConsoleMode, FlushFileBuffers, DecodePointer, WriteConsoleW, GetModuleHandleA, GlobalAlloc, GlobalFree, GetFileSizeEx, CopyFileW, VirtualAlloc, VirtualFree, SystemTimeToTzSpecificLocalTime, GetTimeZoneInformation, SystemTimeToFileTime, GetSystemInfo, VirtualProtect, VirtualQuery, GetComputerNameW, SetCurrentDirectoryW, GetFileType, GetACP, ExitProcess, GetStdHandle, InitializeCriticalSectionAndSpinCount, SetLastError, RtlUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, QueryPerformanceCounter, GetSystemTimeAsFileTime, InitializeSListHead, IsDebuggerPresent, GetStartupInfoW, RaiseException, LoadLibraryExA
                                                                        RPCRT4.dllUuidCreate
                                                                        DescriptionData
                                                                        LegalCopyrightCopyright (c) 2020 Toshiba Tec Corporation, All Rights Reserved.
                                                                        InternalNamesetup
                                                                        FileVersion1.0.4835.18
                                                                        CompanyNameToshiba Tec Corporation
                                                                        ProductNameLenovo Universal Printer 2 driver
                                                                        ProductVersion1.0.4835.18
                                                                        FileDescriptionLenovo Universal Printer 2 driver
                                                                        OriginalFilenameLMSetup.exe
                                                                        Translation0x0409 0x04e4
                                                                        Language of compilation systemCountry where language is spokenMap
                                                                        EnglishUnited States
                                                                        No network behavior found

                                                                        Click to jump to process

                                                                        Target ID:0
                                                                        Start time:23:41:35
                                                                        Start date:28/01/2022
                                                                        Path:C:\Users\user\Desktop\LMSetup.exe
                                                                        Wow64 process (32bit):true
                                                                        Commandline:"C:\Users\user\Desktop\LMSetup.exe"
                                                                        Imagebase:0x8c0000
                                                                        File size:49224728 bytes
                                                                        MD5 hash:C915A8370A016F079ADFEA57CC00B46F
                                                                        Has elevated privileges:true
                                                                        Has administrator privileges:true
                                                                        Programmed in:C, C++ or other language
                                                                        Reputation:low

                                                                        Target ID:5
                                                                        Start time:23:41:38
                                                                        Start date:28/01/2022
                                                                        Path:C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe
                                                                        Wow64 process (32bit):true
                                                                        Commandline:"C:\Windows\Temp\{06CB1A7C-0362-456A-A8DC-276F5C54CBCA}\.cr\LMSetup.exe" -burn.clean.room="C:\Users\user\Desktop\LMSetup.exe" -burn.filehandle.attached=556 -burn.filehandle.self=576
                                                                        Imagebase:0x8e0000
                                                                        File size:8550648 bytes
                                                                        MD5 hash:ED2B2F8988D6123D440982052A65D364
                                                                        Has elevated privileges:true
                                                                        Has administrator privileges:true
                                                                        Programmed in:C, C++ or other language
                                                                        Reputation:low

                                                                        Target ID:21
                                                                        Start time:23:43:09
                                                                        Start date:28/01/2022
                                                                        Path:C:\Windows\SysWOW64\cmd.exe
                                                                        Wow64 process (32bit):true
                                                                        Commandline:cmd" /c C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe "C:\Users\user\Desktop\LMSetup.exe" -nologo -x "C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba
                                                                        Imagebase:0xd80000
                                                                        File size:232960 bytes
                                                                        MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                                                        Has elevated privileges:true
                                                                        Has administrator privileges:true
                                                                        Programmed in:C, C++ or other language
                                                                        Reputation:high

                                                                        Target ID:22
                                                                        Start time:23:43:11
                                                                        Start date:28/01/2022
                                                                        Path:C:\Windows\System32\conhost.exe
                                                                        Wow64 process (32bit):false
                                                                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                        Imagebase:0x7ff7f20f0000
                                                                        File size:625664 bytes
                                                                        MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                        Has elevated privileges:true
                                                                        Has administrator privileges:true
                                                                        Programmed in:C, C++ or other language
                                                                        Reputation:high

                                                                        Target ID:24
                                                                        Start time:23:43:11
                                                                        Start date:28/01/2022
                                                                        Path:C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe
                                                                        Wow64 process (32bit):true
                                                                        Commandline:C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba\dark.exe "C:\Users\user\Desktop\LMSetup.exe" -nologo -x "C:\Windows\Temp\{58155FEA-9500-424F-A76C-4B75D45447D7}\.ba"
                                                                        Imagebase:0xb00000
                                                                        File size:28672 bytes
                                                                        MD5 hash:6F5BF63BB69D04CFBF2BDB336BF3A767
                                                                        Has elevated privileges:true
                                                                        Has administrator privileges:true
                                                                        Programmed in:.Net C# or VB.NET
                                                                        Reputation:low

                                                                        No disassembly